組織的安全性、SSO 與 SCIM
組織「安全性」頁面上的五項控制:身分提供者、要求單一登入、首次登入時建立帳戶、透過 SCIM 進行目錄同步,以及緊急存取。
Available onFreeProMaxEnterprise由擁有者或安全性角色設定。
組織儀表板中的安全性區段包含五個項目。每一項都是獨立的決定,本頁說明它們的內容以及詳細資訊所在位置。
身分提供者
連接您的身分提供者後,成員就能以登入其他服務的相同方式登入,而不需要使用 Dropstone 密碼。同時支援 SAML 與 OIDC。請參閱單一登入。
要求單一登入
提供者連接後,此設定將使其成為組織唯一的登入方式。這是提供 SSO 與強制執行 SSO 之間的差異,值得審慎考量:它適用於所有人,包括擁有者在內。
首次登入時建立帳戶
無需逐一邀請每個人,當某人首次透過提供者登入時,系統便會建立帳戶。這是大多數組織避免成員名冊與目錄脫節的方式。
透過 SCIM 進行目錄同步
SCIM 2.0 讓成員名冊與您的目錄保持同步:新成員自動出現,離職成員自動停用,無需任何人記得手動處理。它與 SSO 相輔相成,而非取代 SSO。請參閱 SCIM 佈建。
緊急存取
當身分提供者本身故障時,這是一條備援的進入途徑。它刻意設計得狹窄且刻意留下紀錄:每一項管理操作(包括透過此途徑執行的操作)都會記錄在稽核日誌中。
此頁面之外的內容
成員可以使用什麼屬於政策而非安全性:模型、連接器、介面、工具與網路規則位於政策中。保留什麼屬於資料區段。建議將這兩個部分與本頁一起閱讀,因為安全性審查通常會同時涵蓋這三個面向。
Related articles
- Single sign-on (SSO)Connect your organization's identity provider so members sign in to Dropstone with their work credentials. SAML 2.0 and OpenID Connect are supported, with just-in-time provisioning of new members.
- SCIM provisioningAutomate joiners, leavers, and team membership in Dropstone from your identity provider using SCIM 2.0. Users and groups are supported. Deprovisioning is a soft delete.
- The organization audit logEvery administrative action in a Dropstone organization is recorded, with filters, ranges, and a CSV or JSON export. What is in it, who can read it, and why nobody can edit it.
- Roles and permissionsThe six roles in a Dropstone organization, what each one may do, why reading member conversations is deliberately not an administrator power, how administrators are appointed, and what the gold verified mark means.
- How an organization manages its dataThe three settings an owner controls for an organization, what each one stores, who can read it, and the limits of the strongest setting. Content logging, product telemetry, and retention, in one place.
- How Dropstone handles your dataWhat Dropstone stores, for how long, who can see it, whether it is used to improve the models, and the commitments that apply to every account. A plain-language summary of Dropstone's data practices.
Ctrl+I