Mixed Authentication / Multiple Provider Single Sign-On
Managing SSO with Mixed Authentication / Multiple Provider Single Sign-On
Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication
| What are Mixed Authentication and Multiple Provider Single Sign-On? |
|---|
| Mixed Authentication allows a community to accept both Single Sign-On (SSO) and IdeaScale Email/Password logins from its members. Multiple Provider Single Sign-On allows a community to offer more than one SSO identity provider (IDP) for members to choose from at login. |
Once Single Sign-On (SAML 2.0 or 3.0) has been set up for a workspace, a Workspace Administrator can additionally enable Mixed Authentication so that members can log in using either Single Sign-On or an IdeaScale Email/Password login, with Single Sign-On remaining the default method (see Exceptions below). A Community Administrator can further enable Multiple Provider Single Sign-On so that members of a community choose from more than one configured identity provider at login.
Role Permissions
- Workspace Administrator: Enables the IdeaScale Email/Password Login option workspace-wide, and controls whether new members can self-register to the workspace using the Allow Workspace Member Registration setting.
- Community Administrator: Selects which members or groups may use the IdeaScale Email/Password Login option through the Members Allowed For Ideascale Email/Password Login and Groups Not Allowed For IdeaScale Email/Password Login fields under Community Settings, and enables or disables Multiple Provider Single Sign-On and manages Identity Provider (IDP) configurations for the community.
- Member: Logs in using either Single Sign-On or an IdeaScale Email/Password login when Mixed Authentication is enabled and access is permitted, registers a new account when Allow Workspace Member Registration is enabled, and selects an identity provider from the login page when Multiple Provider Single Sign-On is enabled for the community.
Enabling IdeaScale Email/Password Login
Workspace Registration
Member Login Experience With Mixed Authentication
Multiple Provider Single Sign-On
Exceptions
Frequently Asked Questions
Enabling IdeaScale Email/Password Login
Once Single Sign-On (SAML 2.0 or 3.0) has been set up for the workspace, the Workspace Administrator can enable the IdeaScale Email/Password Login switch under Settings >> Workspace >> Security >> Authentication. Enabling this switch allows either all members or a selected group, chosen from the Members Allowed For Ideascale Email/Password Login dropdown under Community Settings >> Security >> Community Access Rules, by the Community Administrator to log in using Single Sign-On as well as with an IdeaScale Email/Password login, with Single Sign-On remaining the default login type (see Exceptions below).

Restricting Access by Member or Group
- Members Allowed For Ideascale Email/Password Login: Dropdown under Community Settings >> Security >> Community Access Rules used to select all members or a specific group permitted to use the IdeaScale Email/Password Login option in addition to Single Sign-On.
- Groups Not Allowed For IdeaScale Email/Password Login: Field for specifying one or more groups to exclude from using the IdeaScale Email/Password Login option.

Workspace Registration
By default, a workspace configured with Single Sign-On does not allow new members to self-register (see Exceptions below). The Workspace Administrator can allow new member registration by enabling Allow Workspace Member Registration under Settings >> Workspace >> Workspace Configuration >> Workspace Info >> General Info

Once enabled, members see a Register option on the login screen.

Selecting Register opens the registration page.
Help article on Registration Process
Member Login Experience With Mixed Authentication
When Mixed Authentication is enabled, a member sees both a Single Sign-On login option and a Continue with email button on the login screen.

Selecting Log in With SSO account takes the member to the Single Sign-On login page, where the member logs in using Single Sign-On credentials.

Selecting Log in With IdeaScale takes the member to the standard IdeaScale login page, where the member logs in using IdeaScale login credentials.

Multiple Provider Single Sign-On
IdeaScale supports Multiple Provider Single Sign-On alongside standard Single Sign-On for a community. Each community has its own setting to enable or disable Multiple Provider Single Sign-On and its own set of Identity Provider (IDP) configurations, which can be added, edited, or deleted from community settings.
How Multiple Provider SSO Works
When Multiple Provider Single Sign-On is enabled for a community, the community login page displays a list of the enabled IDP configurations. A member selects the desired identity provider from the list to log in to the community.

Help Article for SAML Single Sign-On at IdeaScale
Exceptions
- Default Login Type: When Mixed Authentication permits a member to log in using either Single Sign-On or an IdeaScale Email/Password login, Single Sign-On is the default login type.
- Workspace Registration Disabled by Default: New members cannot self-register to a workspace configured with Single Sign-On unless the Workspace Administrator enables Allow Workspace Member Registration.
- Group-Level Restriction (TO BE VERIFIED): A group listed under Groups Not Allowed For IdeaScale Email/Password Login may be excluded from using the IdeaScale Email/Password Login option even if members are broadly permitted under Members Allowed For Ideascale Email/Password Login; the source does not explicitly confirm this override relationship.
Frequently Asked Questions
What does Mixed Authentication allow a member to do?
Mixed Authentication allows a member to log in to a community using either Single Sign-On or an IdeaScale Email/Password login, depending on whether the member has been added to the active directory and permitted to use the IdeaScale Email/Password Login option.
Can access to IdeaScale Email/Password Login be limited to specific members or groups?
Yes. The Community Administrator can select all members or a specific group under Members Allowed For Ideascale Email/Password Login, and can separately exclude one or more groups using Groups Not Allowed For IdeaScale Email/Password Login.
Can a new member register for a workspace that uses Single Sign-On?
Only if the Workspace Administrator has enabled Allow Workspace Member Registration. By default, new member self-registration is not allowed on a workspace configured with Single Sign-On.
What is Multiple Provider Single Sign-On?
Multiple Provider Single Sign-On is a community-level setting that allows more than one Identity Provider (IDP) configuration to be enabled for a single community, in addition to standard Single Sign-On.
How does a member choose which identity provider to use when Multiple Provider Single Sign-On is enabled?
The community login page displays a list of the enabled IDP configurations, and the member selects the desired identity provider from that list to log in.
Related Articles
- Help Article for Workspace Authentication
- Help Article for Workspace Single Sign-On Settings
- Help Article for SAML Single Sign-On at IdeaScale
- Help Article for 2 Step Authentication
- Help Article for Registration Process
Last Updated: August 15, 2026