The short answer: SSO admins in Command Center can maintain a list of specific email addresses that are exempt from SSO enforcement, so those users can still log in with a password even after SSO is required for everyone else on your domain.
This replaces the previous behavior where all Command Center owners and admins automatically bypassed SSO. Bypass access is now explicit and managed through this list.
Who Can Manage the Exemption List
Any user with access to manage SSO in Command Center can manage the exemption list — today, that's owners and admins with Command Center access. Management is fully self-serve; no action from Proof support is required.
View and Manage the Exemption List
The exemption list lives on the same screen where you configure SSO for your domain:
Add a User to the Exemption List
How you add a user depends on whether they belong to your organization's tree:
In-tree users +
If the user is a member of your org tree, search for and select them from the user dropdown. Once added, they can sign in with either SSO or a password.
Out-of-tree users +
If the user shares your domain but lives in a different org tree, add them by typing their email address directly. Because they can't successfully authenticate through your IDP, they'll be presented with password login only. Out-of-tree users are labeled "Not in directory — added by domain" so you can tell them apart from in-tree users at a glance.
MFA Is Required for Exempted Users
What Doesn't Change
Adding someone to the exemption list only affects how they log in — it doesn't change their role or permissions in Command Center.
Every change to the exemption list is recorded in the Security Events API and the Keystone audit log, so you have a full history of who was added or removed and when.
Summary Checklist
- Find the exemption list under Security → Identity providers → Details and Policies for your domain.
- Add in-tree users via the dropdown, and out-of-tree users by email address.
- Your Command Center owner is always on the list and can't be removed.
- MFA is required for exempted users logging in with a password.
- All changes appear in the Security Events API and Keystone audit log.
Updated