Change SAML instructions to not use email for NameID #6659
+20
−13
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What are you changing in this pull request and why?
This updates the documentation to no longer instruct admins to configure email addresses as the SAML name identifier (
NameID
) for users. Instead, they are encouraged to pick a value that is stable across email address changes. Specific recommendations are made for Okta, OneLogin, and Entra ID. Google Workspace does not, as best I can find, offer a value as part of the default user profile that is suitable.This will allow admins to change users' email addresses in the IdP, and dbt Cloud will no longer see the user as a new user on the next login. That is currently what happens, it requires manual effort from CSEs and engineers to get users access to the proper user in dbt Cloud again.
Checklist