Audience: Organizations with Command Center

The short answer: SSO admins in Command Center can maintain a list of specific email addresses that are exempt from SSO enforcement, so those users can still log in with a password even after SSO is required for everyone else on your domain.

This replaces the previous behavior where all Command Center owners and admins automatically bypassed SSO. Bypass access is now explicit and managed through this list.


Who Can Manage the Exemption List

Any user with access to manage SSO in Command Center can manage the exemption list — today, that's owners and admins with Command Center access. Management is fully self-serve; no action from Proof support is required.

⚠️
Your Command Center owner is automatically included on the exemption list and can't be removed. This preserves the "break glass" account that can always recover access if SSO is misconfigured.

View and Manage the Exemption List

The exemption list lives on the same screen where you configure SSO for your domain:

1 In Command Center, click Security from the left menu, then select Identity providers.
2 Select Details and Policies for the domain you'd like to update.
3 Scroll to the Excluded Users section under Authentication settings.
Authentication settings screen showing the Excluded Users section with a list of exempted users and their email addresses

Add a User to the Exemption List

How you add a user depends on whether they belong to your organization's tree:

In-tree users +

If the user is a member of your org tree, search for and select them from the user dropdown. Once added, they can sign in with either SSO or a password.

Out-of-tree users +

If the user shares your domain but lives in a different org tree, add them by typing their email address directly. Because they can't successfully authenticate through your IDP, they'll be presented with password login only. Out-of-tree users are labeled "Not in directory — added by domain" so you can tell them apart from in-tree users at a glance.

💡
This is what unblocks SSO for customers with complex org trees — for example, an organization whose users share a domain with a separate child org tree can now exempt just those users instead of leaving SSO off for everyone.

MFA Is Required for Exempted Users

⚠️
Multi-factor authentication (MFA) is mandatory, not optional, for any exempted user logging in with a password. You'll be required to set it up the first time you log in with a password after being added to the list.

What Doesn't Change

Adding someone to the exemption list only affects how they log in — it doesn't change their role or permissions in Command Center.

Every change to the exemption list is recorded in the Security Events API and the Keystone audit log, so you have a full history of who was added or removed and when.


Summary Checklist

  • Find the exemption list under Security → Identity providers → Details and Policies for your domain.
  • Add in-tree users via the dropdown, and out-of-tree users by email address.
  • Your Command Center owner is always on the list and can't be removed.
  • MFA is required for exempted users logging in with a password.
  • All changes appear in the Security Events API and Keystone audit log.

i
Still unsure? Contact your Customer Success Manager (CSM) or submit a support request for help.

Updated

Was this article helpful?

0 out of 0 found this helpful