Dropstone Support

Security, SSO, and SCIM for an organization

The five controls on the organization's Security page: an identity provider, requiring single sign-on, provisioning on first sign-in, directory sync over SCIM, and emergency access.

Available onFreeProMaxEnterpriseSet by the owner, or the security role.

The Security section of your organization dashboard is five things. Each one is a separate decision, and this page says what they are and where the detail lives.


Identity provider

Connect your identity provider and members sign in the way they sign in to everything else, rather than with a Dropstone password. Both SAML and OIDC are supported. See Single sign-on.


Require single sign-on

Once the provider is connected, this makes it the only way in for the organization. It is the difference between offering SSO and enforcing it, and it is worth being deliberate about: it applies to everyone, the owner included.


Create accounts on first sign-in

Instead of inviting each person, an account is created the first time someone signs in through the provider. This is how most organizations avoid a roster that drifts from the directory.


Directory sync over SCIM

SCIM 2.0 keeps the roster in step with your directory: joiners appear, and leavers are deactivated, without anyone remembering to do it. It works alongside SSO rather than instead of it. See SCIM provisioning.


Emergency access

A way back in if the identity provider is the thing that is broken. It is deliberately narrow and deliberately logged: every administrative action, including the ones taken through it, lands in the audit log.


What sits outside this page

What members can use is policy, not security: models, connectors, surfaces, tools, and network rules live in Policies. What is kept is the Data section. Both are worth reading together with this page, since a security review usually asks about all three.


Related articles

Ctrl+I