3 ms·
To be honest, I find it very difficult to argue against the point you're making. I think it is somewhat logical to have SSO be the demarcation between individu
by mattrp 7y ago
To be honest, I find it very difficult to argue against the point you're making. I think it is somewhat logical to have SSO be the demarcation between individuals and enterprise, but if I rewind a decade or so, I imagine the line then was HTTPS (which today is totally ridiculous -- everything is/should be HTTPS). If I could go one step further, I think it's completely wrong for SaaS to blunt force security policies on user's accounts (i.e. ACME would like the ability to read/write to your Google profile). I think enterprises should be able to enforce their policies on the SaaS provider rather than the other way around. And to build for that...I think is going to be a little more complex than a typical user/pass. Maybe everything should be a little more expensive?
- eropple 7y agoThere's a whole tier between "individual" and "enterprise", though, and it's called "small business" and they probably have a lot more of your (and my) stuff than we'd be comfortable having YOLOed around. ;) Enterprises forcing their policies is pretty easy if they're an SP to your directory, FWIW. I've had great success with Okta for this, but I've written SPs that talk to arbitrary OIDC providers and it works pretty well too.