Skip to content

Commit b608f98

Browse files
adamrr724Adam Ross RussellCopilot
authored
Document that IdP gallery apps are out of scope in Government Cloud (#61267)
Co-authored-by: Adam Ross Russell <adamrr@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 8637b42 commit b608f98

5 files changed

Lines changed: 10 additions & 1 deletion

File tree

content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-oidc-for-enterprise-managed-users.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,8 @@ To change the lifetime policy property, you will need the object ID associated w
3636

3737
Support for OIDC is available for customers using Entra ID.
3838

39+
{% data reusables.enterprise-accounts.gov-cloud-idp-not-supported %}
40+
3941
Each Entra ID tenant can support only one OIDC integration with {% data variables.product.prodname_emus %}. If you want to connect Entra ID to more than one enterprise on {% data variables.product.prodname_dotcom %}, use SAML instead. See [AUTOTITLE](/admin/identity-and-access-management/using-enterprise-managed-users-for-iam/configuring-saml-single-sign-on-for-enterprise-managed-users).
4042

4143
OIDC does not support IdP-initiated authentication.

content/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,8 @@ With {% data variables.product.prodname_emus %}, access to your enterprise's res
2727

2828
After you configure SAML SSO, we recommend storing your recovery codes so you can recover access to your enterprise in the event that your IdP is unavailable.
2929

30+
{% data reusables.enterprise-accounts.gov-cloud-idp-not-supported %}
31+
3032
{% data reusables.enterprise_user_management.SAML-to-OIDC-migration-for-EMU %}
3133

3234
## Prerequisites

content/admin/managing-iam/provisioning-user-accounts-with-scim/configuring-scim-provisioning-for-users.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -26,6 +26,8 @@ category:
2626

2727
If you use a partner IdP, you can simplify the configuration of SCIM provisioning by using the partner IdP's application. If you don't use a partner IdP for provisioning, you can implement SCIM using calls to {% data variables.product.company_short %}'s REST API for SCIM. For more information, see {% ifversion ghec %}[AUTOTITLE](/admin/managing-iam/understanding-iam-for-enterprises/about-enterprise-managed-users#identity-management-systems).{% else %}[AUTOTITLE](/admin/managing-iam/provisioning-user-accounts-with-scim/user-provisioning-with-scim-on-ghes#supported-identity-providers).{% endif %}
2828

29+
{% data reusables.enterprise-accounts.gov-cloud-idp-not-supported %}
30+
2931
{% ifversion ghes %}
3032

3133
## Who needs to follow these instructions?

content/admin/managing-iam/using-saml-for-enterprise-iam/configuring-saml-single-sign-on-for-your-enterprise.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,11 +65,13 @@ If an unauthenticated user attempts to sign in to {% data variables.location.pro
6565

6666
For more information about connecting Microsoft Entra ID (previously known as Azure AD) to your enterprise, see [Tutorial: Microsoft Entra SSO integration with GitHub Enterprise Cloud - Enterprise Account](https://learn.microsoft.com/en-us/entra/identity/saas-apps/github-enterprise-cloud-enterprise-account-tutorial) in Microsoft Docs.
6767

68+
{% data reusables.enterprise-accounts.gov-cloud-idp-not-supported %}
69+
6870
{% elsif ghes %}
6971

7072
For more information about connecting Entra ID to your enterprise, see [Tutorial: Microsoft Entra SSO integration with GitHub Enterprise Server](https://learn.microsoft.com/en-us/entra/identity/saas-apps/github-ae-tutorial) in Microsoft Docs.
7173

72-
We do not have a supported partner application when using Entra ID for Azure Government.
74+
{% data reusables.enterprise-accounts.gov-cloud-idp-not-supported %}
7375

7476
## Username considerations with SAML
7577

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
> [!NOTE] {% data variables.product.company_short %} does not test or validate identity provider (IdP) gallery applications for use in Government Cloud environments, including Microsoft Entra ID Government Cloud and Okta Government Cloud. Authentication and SCIM provisioning issues that involve gallery applications in these environments fall outside {% data variables.product.company_short %}'s [scope of support](/support/learning-about-github-support/about-github-support#scope-of-support).

0 commit comments

Comments
 (0)