ThreatPrevent
ThreatPrevent
Cyber Trust Intelligence
Enterprise SSO

Mandatory SSO enforcement

After successful testing, owners and administrators can require company SSO for their organisation. ThreatPrevent applies a fixed seven-day grace period before activation.

Optional

SSO is offered and email-code sign-in remains available.

Scheduled

A seven-day grace period is active. Continue testing all users and extension installations.

Active

Email-code access to the enforced organisation is blocked. SSO assurance is checked on every portal request.

What activation changes

  • Portal access to the organisation requires an SSO-authenticated session for that exact organisation.
  • Existing browser-extension sessions that were not established through SSO are revoked.
  • Users in several organisations retain access to non-enforced organisations through their permitted authentication methods.
  • Provider, verified-domain and policy settings are locked while enforcement is scheduled or active; cancel or disable enforcement before changing them.
  • Revoked extension sessions do not become valid again if enforcement is later disabled.

Emergency access

A ThreatPrevent platform administrator with the security permission and recent MFA verification can create a temporary email-login bypass. A reason is mandatory, the duration must be between 15 minutes and 24 hours, and the action is audited. The bypass expires automatically.

Use emergency bypass only for a confirmed identity-provider outage or recovery incident. It does not repair the provider configuration.

Rollback

Before activation, select Cancel schedule. After activation, select Disable enforcement to restore email-code fallback. Both actions are recorded. Provider changes can then be made and tested before enforcement is scheduled again.