# SSO and ISC direct connected Applications

**URL:** <https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642>\
**Category:** SHF Discussion and Questions\
**Tags:** connectors, identity-security-cloud\
**Created:** [October 16, 2024, 2:13pm UTC](https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642 "2024-10-16T14:13:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ccarlton](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@ccarlton](https://developer.sailpoint.com/discuss/u/ccarlton)\
**Post date:** [October 16, 2024, 2:13pm UTC](https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642/1 "2024-10-16T14:13:01Z")

</div>

[SSO, IDN and Sources – Apps that require an entitlement from more than one source - Identity Security Cloud (ISC) / ISC Discussion and Questions - SailPoint Developer Community](https://developer.sailpoint.com/discuss/t/sso-idn-and-sources-apps-that-require-an-entitlement-from-more-than-one-source/23534)  
@KevinHarrington @alexandre_mazars

Talks about how to handle applications that have a ISC connector (Like Box for example) but also your organization uses SSO (like through Azure AD) and that SSO requires a Security group as well. (the idea that access to BOX requires actions in two different sources – AAD (to get the SSO Group) and BOX (to get the user account within the BOX Application).

I lost track of that thread, and it’s now locked, so I’m going to follow up…

- Our organization does not use requestable Roles.
- We use requestable access profiles, organized under applications (for categorization).
- We only use Roles for automated (rule based) access.

One of the replies in that thread talks about using a Role to handle the SSO group.

> Set up a role that looks for an active account on the application, and if the user has it - add them to the SSO group for that app.

I like that idea… A person can still request an access profile in box, and then once that access profile is approved and they have an account in that box source, the ‘secondary SSO access profile’ gets automatically added, because a box account was detected by a role.

But what is the role’s selection criteria? For example, there isn’t a “has Account in source” criteria (though it would be nice).  
Is there a way to achieve a similar result using the criteria that is there?

---

<div class="post-metadata">

**Author:** ![alexandre\_mazars](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/alexandre_mazars/32/2860_2.png) [@alexandre\_mazars](https://developer.sailpoint.com/discuss/u/alexandre_mazars)\
**Post date:** [October 16, 2024, 2:32pm UTC](https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642/2 "2024-10-16T14:32:39Z")

</div>

Hello @ccarlton,

For the role criteria, we are often using the mail attribute in the SaaS App source. We are using the criteria “email contains @domain.com”. We have also used criterias on the uid or the SAML Object in the SaaS Apps when the mail is not used in the connector.

Hope it will help you.  
Regards,

Alexandre

---

<div class="post-metadata">

**Author:** ![ccarlton](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@ccarlton](https://developer.sailpoint.com/discuss/u/ccarlton)\
**Post date:** [October 16, 2024, 2:37pm UTC](https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642/3 "2024-10-16T14:37:58Z")

</div>

Thanks! So there is a way to get a similar result…

I’m definitely going to use this route… thanks for the idea!

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [December 15, 2024, 2:38pm UTC](https://developer.sailpoint.com/discuss/t/sso-and-isc-direct-connected-applications/85642/4 "2024-12-15T14:38:14Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
