Enforcing SSO and staying out of trouble
Overview
Once SSO is configured and verified, enforcement makes it the only way in for your team. Enforcement lives on the Enforcement card of Settings → SSO, with a status badge showing Enforced or Not enforced.
The pre-flight check
Arthiva runs the pre-flight automatically and shows either "Ready to enforce" or "Not ready — fix these first" with the full list of blockers. The Enable enforcement button stays disabled until every blocker is cleared. It checks that:
- the IdP entity ID, SSO URL, and X.509 certificate are all present, and
- the org has at least one active organization admin.
Admins keep a break-glass path
With enforcement on, everyone must sign in through SSO — except organization admins, who can always fall back to email + password. That's deliberate: if your IdP has an outage or a certificate expires, an admin can still get in and fix or disable SSO. Disabling enforcement is always allowed, whatever state the configuration is in.
Certificate expiry warnings
Arthiva checks your IdP signing certificate daily and emails every active organization admin when it's within 30 days of expiring, with weekly reminders until it's rotated. Updating the certificate in settings resets the warnings.
Removing SSO
The Remove SSO configuration card deletes all SSO settings; users fall back to email + password, and enforcement (if on) turns off automatically. This can't be undone — you'd set SSO up again from scratch.
Related guides
Can't find what you need?
Email support@arthiva.ai or use the contact page — we aim to respond within two business days.
Contact support