Decube
Try for free
  • 🚀Overview
    • Welcome to decube
    • Getting started
      • How to connect data sources
    • Security and Compliance
    • Data Policy
    • Changelog
    • Public Roadmap
  • 🔌Data Warehouses
    • Snowflake
    • Redshift
    • Google Bigquery
    • Databricks
    • Azure Synapse
  • 🔌Relational Databases
    • PostgreSQL
    • MySQL
    • SingleStore
    • Microsoft SQL Server
    • Oracle
  • 🔌Transformation Tools
    • dbt (Cloud Version)
    • dbt Core
    • Fivetran
    • Airflow
    • AWS Glue
    • Azure Data Factory
    • Apache Spark
      • Apache Spark in Azure Synapse
    • OpenLineage (BETA)
    • Additional configurations
  • 🔌Business Intelligence
    • Tableau
    • Looker
    • PowerBI
  • 🔌Data Lake
    • AWS S3
    • Azure Data Lake Storage (ADLS)
      • Azure Function for Metadata
    • Google Cloud Storage (GCS)
  • 🔌Ticketing and Collaboration
    • ServiceNow
    • Jira
  • 🔒Security and Connectivity
    • Enabling VPC Access
    • IP Whitelisting
    • SSH Tunneling
    • AWS Identities
  • ✅Data Quality
    • Incidents Overview
    • Incident model feedback
    • Enable asset monitoring
    • Available Monitor Types
    • Available Monitor Modes
    • Catalog: Add/Modify Monitor
    • Set Up Freshness & Volume Monitors
    • Set Up Field Health Monitors
    • Set Up Custom SQL Monitors
    • Grouped-by Monitors
    • Modify Schema Drift Monitors
    • Modify Job Failure Monitors (Data Job)
    • Custom Scheduling For Monitors
    • Config Settings
  • 📖Catalog
    • Overview of Asset Types
    • Assets Catalog
    • Asset Overview
    • Automated Lineage
      • Lineage Relationship
      • Supported Data Sources and Lineage Types
    • Add lineage relationships manually
    • Add tags and classifications to fields
    • Field Statistcs
    • Preview sample data
  • 📚Glossary
    • Glossary, Category and Terms
    • Adding a new glossary
    • Adding Terms and Linked Assets
  • Moving Terms to Glossary/Category
  • AI Copilot
    • Copilot's Autocomplete
  • 🤝Collaboration
    • Ask Questions
    • Rate an asset
  • 🌐Data Mesh [BETA]
    • Overview on Data Mesh [BETA]
    • Creating and Managing Domains/Sub-domains
    • Adding members to Domain/Sub-domain
    • Linking Entities to Domains/Sub-domains
    • Adding Data Products to Domains/Subdomains
    • Creating a draft Data Asset
    • Adding a Data Contract - Default Settings
    • Adding a Data Contract - Freshness Test
    • Adding a Data Contract - Column Tests
    • Publishing the Data Asset
  • 🏛️Governance
    • Governance module
    • Classification Policies
    • Auto-classify data assets
  • ☑️Approval Workflow
    • What are Change Requests?
    • Initiate a change request
    • What are Access Requests?
    • Initiate an Access Request
  • 📑Data reconciliation
    • Adding a new recon
    • Understand your recon results
    • Supported sources for Recon
  • 📋Reports
    • Overview of Reports
    • Supported sources for Reports
    • Asset Report: Data Quality Scorecard
  • 📊Dashboard
    • Dashboard Overview
    • Incidents
    • Quality
  • ⏰Alert Notifications
    • Get alerts on email
    • Connect your Slack channels
    • Connect to Microsoft Teams
    • Webhooks integration
  • 🏛️Manage Access
    • User Management - Overview
    • Invite users
    • Deactivate or re-activate users
    • Revoke a user invite
  • 🔐Group-based Access Controls
    • Groups Management - Overview
    • Create Groups & Assign Policies
    • Source-based Policies
    • Administrative-based Policies
    • Module-based Policies
    • What is the "Owners" group?
  • 🗄️Org Settings
    • Multi-factor authentication
    • Single Sign-On (SSO) with Microsoft
    • Single Sign-On (SSO) with JumpCloud
  • ❓Support
    • Supported Features by Integration
    • Frequently Asked Questions
    • Supported Browsers and System Requirements
  • Public API (BETA)
    • Overview
      • Data API
        • Glossary
        • Lineage
        • ACL
          • Group
      • Control API
        • Users
    • API Keys
Powered by GitBook
On this page
  • Linking and Enabling SSO for your organization
  • Unlink SSO in your organization
  1. Org Settings

Single Sign-On (SSO) with Microsoft

Here's how you can use your organization's Microsoft account to log into decube directly.

PreviousMulti-factor authenticationNextSingle Sign-On (SSO) with JumpCloud

Last updated 11 months ago

Users now have the option to use Single Sign-On (SSO) for Microsoft Entra (formerly Azure Active Directory), enhancing the security and efficiency of user logins.

Without SSO-enabled, users log into the Decube app using their registered email and password. However, when SSO is linked and enabled for the organization, users must log in using Microsoft using their organization's Microsoft/Azure account to access Decube's application.

Linking and Enabling SSO for your organization

You may enforce SSO in your organization by navigating to the My Account > Org Settings page.

You will need to be an Owner or have permission to access the Org Settings in the Group-based Access Controls.

You will need to click on Enable Sudo mode to make changes on this page. You will receive a verification step to confirm the One Time Passcode (OTP) which is sent to your email before you can proceed to the next step.

You will need to check your email and enter the OTP sent to your registered email, such as the example below.

Upon entering the OTP correctly on the verification modal, you will then be able to turn on the toggle under the "Single Sign-On" option.

Upon toggling this on, you may be redirected to a page to sign in to your Microsoft account. Once you have successfully signed in, you will be redirected back to Decube's Org settings page with the toggle switched on.

As the first user in the organization to enable SSO, you will need the administrative privilege on Microsoft to grant consent to applications.

Once SSO has been enabled, all users in your organization will then receive an email as below, indicating that Microsoft SSO has been enforced on their org, and their initially registered Decube password credentials will be invalid.

Unlink SSO in your organization

Unlink Single Sign-On (SSO) for your organization follows a very similar flow to Linking SSO, simply navigate to My Account > Org Settings.

You must first "Enable Sudo Mode" and go through the verification process. After that, you simply have to click on the toggle under the SSO option to disable it.

Once SSO has been successfully disabled, the users under your organization will also receive an email notification that SSO has been disabled on your organisation which example is shown below.

Due to the previous enforcement of SSO, users must now set a new password for their Decube account before they can log in. They can do so by clicking on the Set a new password for my account option on their registered email, or go to the sign in page and click on Forget password.

Note for Admins: Admin consent workflow gives admins a secure way to grant access to applications that require admin approval. For more information, see .

To grant tenant-wide admin consent to an application in Microsoft Entra ID and understand how to configure individual user consent settings, see . To assign users and groups to an enterprise application in Microsoft Entra ID, .

🗄️
Configure Admin Consent Workflow
Grant tenant-wide admin consent to an application
learn more here
An email OTP
Email sent to all users that SSO has been enforced.
Click on the toggle to disable SSO in your organization.
Email sent to all users that SSO has been disabled.