Enabling SSO and Managing Your SSO Policy
As the designated SSO Administrator, the Primary Account Owner (PAO) holds exclusive control over configuring the Single Sign-On feature and setting the authentication policy for the entire 101domain account.
This centralized control allows the PAO to manage the single designated Identity Provider (IdP) for all users and enforce specific SSO settings, while disabling password-based login functionality for accounts set to SSO Only.
The system allows only one IdP to be designated for all users on an account but allows the SSO settings to vary per user.
If a user is set to SSO Only, then all password-based functionality is disabled, including password resets.