Skip to content
English
  • There are no suggestions because the search field is empty.

Mixed Authentication / Multiple Provider Single Sign-On

Managing SSO with Mixed Authentication / Multiple Provider Single Sign-On

Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication

What are Mixed Authentication and Multiple Provider Single Sign-On?
Mixed Authentication allows a community to accept both Single Sign-On (SSO) and IdeaScale Email/Password logins from its members. Multiple Provider Single Sign-On allows a community to offer more than one SSO identity provider (IDP) for members to choose from at login.

Once Single Sign-On (SAML 2.0 or 3.0) has been set up for a workspace, a Workspace Administrator can additionally enable Mixed Authentication so that members can log in using either Single Sign-On or an IdeaScale Email/Password login, with Single Sign-On remaining the default method (see Exceptions below). A Community Administrator can further enable Multiple Provider Single Sign-On so that members of a community choose from more than one configured identity provider at login.


Role Permissions

  1. Workspace Administrator: Enables the IdeaScale Email/Password Login option workspace-wide, and controls whether new members can self-register to the workspace using the Allow Workspace Member Registration setting.
  2. Community Administrator: Selects which members or groups may use the IdeaScale Email/Password Login option through the Members Allowed For Ideascale Email/Password Login and Groups Not Allowed For IdeaScale Email/Password Login fields under Community Settings, and enables or disables Multiple Provider Single Sign-On and manages Identity Provider (IDP) configurations for the community.
  3. Member: Logs in using either Single Sign-On or an IdeaScale Email/Password login when Mixed Authentication is enabled and access is permitted, registers a new account when Allow Workspace Member Registration is enabled, and selects an identity provider from the login page when Multiple Provider Single Sign-On is enabled for the community.


Enabling IdeaScale Email/Password Login

Once Single Sign-On (SAML 2.0 or 3.0) has been set up for the workspace, the Workspace Administrator can enable the IdeaScale Email/Password Login switch under Settings >> Workspace >> Security >> Authentication. Enabling this switch allows either all members or a selected group, chosen from the Members Allowed For Ideascale Email/Password Login dropdown under Community Settings >> Security >> Community Access Rules, by the Community Administrator to log in using Single Sign-On as well as with an IdeaScale Email/Password login, with Single Sign-On remaining the default login type (see Exceptions below).

Screenshot 2026-06-18 at 10.50.12 AM

Restricting Access by Member or Group

  1. Members Allowed For Ideascale Email/Password Login: Dropdown under Community Settings >> Security >> Community Access Rules used to select all members or a specific group permitted to use the IdeaScale Email/Password Login option in addition to Single Sign-On.
  2. Groups Not Allowed For IdeaScale Email/Password Login: Field for specifying one or more groups to exclude from using the IdeaScale Email/Password Login option.

Screenshot 2024-09-24 at 11.02.03 PM


Workspace Registration 

By default, a workspace configured with Single Sign-On does not allow new members to self-register (see Exceptions below). The Workspace Administrator can allow new member registration by enabling Allow Workspace Member Registration under Settings >> Workspace >> Workspace Configuration >> Workspace Info >> General Info

ws registration copy

Once enabled, members see a Register option on the login screen.

Screenshot 2025-02-26 at 8.21.54 PM

Selecting Register opens the registration page.

Help article on Registration Process


Member Login Experience With Mixed Authentication

When Mixed Authentication is enabled, a member sees both a Single Sign-On login option and a Continue with email button on the login screen.

mixed sso login copy

Selecting Log in With SSO account takes the member to the Single Sign-On login page, where the member logs in using Single Sign-On credentials.

downloads.intercomcdn.comio15808616285e11466e10c93f5d355e9c0image

Selecting Log in With IdeaScale takes the member to the standard IdeaScale login page, where the member logs in using IdeaScale login credentials.

sso login email copy


Multiple Provider Single Sign-On

IdeaScale supports Multiple Provider Single Sign-On alongside standard Single Sign-On for a community. Each community has its own setting to enable or disable Multiple Provider Single Sign-On and its own set of Identity Provider (IDP) configurations, which can be added, edited, or deleted from community settings.

How Multiple Provider SSO Works

When Multiple Provider Single Sign-On is enabled for a community, the community login page displays a list of the enabled IDP configurations. A member selects the desired identity provider from the list to log in to the community.

Screenshot 2024-09-24 at 11 copy

Help Article for SAML Single Sign-On at IdeaScale


Exceptions

  1. Default Login Type: When Mixed Authentication permits a member to log in using either Single Sign-On or an IdeaScale Email/Password login, Single Sign-On is the default login type.
  2. Workspace Registration Disabled by Default: New members cannot self-register to a workspace configured with Single Sign-On unless the Workspace Administrator enables Allow Workspace Member Registration.
  3. Group-Level Restriction (TO BE VERIFIED): A group listed under Groups Not Allowed For IdeaScale Email/Password Login may be excluded from using the IdeaScale Email/Password Login option even if members are broadly permitted under Members Allowed For Ideascale Email/Password Login; the source does not explicitly confirm this override relationship.

Frequently Asked Questions

What does Mixed Authentication allow a member to do?

Mixed Authentication allows a member to log in to a community using either Single Sign-On or an IdeaScale Email/Password login, depending on whether the member has been added to the active directory and permitted to use the IdeaScale Email/Password Login option.

Can access to IdeaScale Email/Password Login be limited to specific members or groups?

Yes. The Community Administrator can select all members or a specific group under Members Allowed For Ideascale Email/Password Login, and can separately exclude one or more groups using Groups Not Allowed For IdeaScale Email/Password Login.

Can a new member register for a workspace that uses Single Sign-On?

Only if the Workspace Administrator has enabled Allow Workspace Member Registration. By default, new member self-registration is not allowed on a workspace configured with Single Sign-On.

What is Multiple Provider Single Sign-On?

Multiple Provider Single Sign-On is a community-level setting that allows more than one Identity Provider (IDP) configuration to be enabled for a single community, in addition to standard Single Sign-On.

How does a member choose which identity provider to use when Multiple Provider Single Sign-On is enabled?

The community login page displays a list of the enabled IDP configurations, and the member selects the desired identity provider from that list to log in.


Related Articles

 

Last Updated: August 15, 2026