X Tutup
The Wayback Machine - https://web.archive.org/web/20210131130116/https://github.com/github/roadmap/issues/132
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enterprise-Managed Users (Beta) #132

Open
github-product-roadmap opened this issue Oct 7, 2020 · 0 comments
Open

Enterprise-Managed Users (Beta) #132

github-product-roadmap opened this issue Oct 7, 2020 · 0 comments

Comments

@github-product-roadmap
Copy link
Collaborator

@github-product-roadmap github-product-roadmap commented Oct 7, 2020

Summary
GitHub Enterprise Managed Users (EMUs) are a new type of user account aimed for professional use on GitHub Enterprise Cloud (GHEC). EMUs are provisioned and managed via an enterprise's identity provider (IdP), providing companies with user lifecycle control and enhanced security.

Intended Outcome
Enterprises using EMUs can create user accounts for their employees via a linked IdP. Administrators are also able to manage user profile data (e.g. display name, email address, etc.) and membership to GitHub teams through their IdP.

How will it work?
After setting up a link between a GHEC account and a supported IdP, enterprises will be able to enable SAML (Security Assertion Markup Language) with SCIM (System for Cross-domain Identity Management) to manage the user provisioning lifecycle of EMUs. Once the EMU account is created, the user will get an invite email leading them to complete single sign-on (SSO) and gain access to their provisioned organization(s). In this release, EMU accounts will only be able to contribute (e.g. open issues, create pull requests) to repositories in organizations owned by their GitHub Enterprise Cloud account. EMUs will have read-only access to public repositories on GitHub.com, but will not be able to make contributions to public repos. We anticipate enabling policy for public contributions in a future release.

Membership to GitHub teams will also be managed through the enterprise's IdP. Administrators may add users to groups in their IdP and, via SCIM, those groups memberships will be reflected on teams in the enterprise's organizations. Administrators are then able to add those teams to repositories and assign roles on GitHub. In addition, enterprise owners will be able to audit the activity of EMUs in their enterprise account.

As part of the initiative we will be improving our authentication functionality to create a true SSO experience for customers using EMU-enabled Enterprises. Please find a screenshot of our in-progress development below:
SSOLogin-Oct2_2020

Note: For the initial implementation of EMUs we will be optimizing for AzureAD and Okta as the IdP.

@github github locked and limited conversation to collaborators Oct 7, 2020
@github-product-roadmap github-product-roadmap added this to Q1 2021 – Jan-Mar in GitHub public roadmap Oct 7, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
GitHub public roadmap
Q1 2021 – Jan-Mar
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
1 participant
X Tutup