nullsenseN
ZITADELβ€’2mo agoβ€’
7 replies
nullsense

How do I remove a users Zitadel password once they are associated with an external IdP

🏬Self-hostedπŸ”Authentication⛓️‍πŸ’₯APIsπŸͺ΅Login❓Question
As the question states, we require that the user's Zitadel password be removed once the user is associated with an external IdP. We handle this on a user-per-user basis, so we cannot remove the login using username and password on the instance or org level. How can we prevent this user from having a password when they're associated with an external IdP? (This is a backdoor security risk).

The thread Linking external (IdP) users to preconfigured Zitadel users - change password enforced. does not solve this issue.
Was this page helpful?