Open sengi opened 9 months ago
Is this because people aren't authenticating via SSO once they've got an account, or is this because the groups only sync on initial account creation?
TFC ~definitely~ is supposed to require all users except org owners to authn via SSO in order to access projects owned by the org, so I don't think it's the first one. Perhaps the second one? (I haven't looked into it myself.)
We have Terrform Cloud hooked up to Google Workspace for single-sign-on, but it isn’t assigning groups to people correctly. Pretty sure it used to work back when we first started using TFC.
This means we’re having to manually assign groups as people request them, which is toil (and raises the chance of mistakes).