Entra ID as IDP
Hey team, does anyone know if Entra with Pure1 as the Data Protection provider works? Also, is it possible to have a local account (glassbreak account) if the IDP is down?
Hello, I hope the documentation was helpful. Here is a more comprehensive answer for both your questions.
Entra ID as your IdP for Pure1: Yes, this works. Pure1 supports single sign-on via SAML 2.0, and Microsoft Entra ID is a supported identity provider. You configure Pure1 as the service provider (SAML application) on the Entra side and exchange the metadata, after which your Entra users authenticate into Pure1 through your normal corporate login. The Pure1 SSO setup steps in the documentation walk through the IdP-side configuration.
Local / break-glass account if the IdP is down: There isn't a dedicated standalone local account that bypasses SSO today. If your identity provider becomes unavailable, the supported recovery path is to open a support ticket to have SSO temporarily disabled, which lets you sign back in with the original (pre-SSO) Pure1 credentials. Keep in mind those legacy credentials are still subject to standard password policies, so if they have not been used in a while you may also need to reset the password as part of that process.
We recognize a true break-glass / emergency local login is a common ask, and persistent local access independent of the IdP is something we are tracking for future identity platform improvements.
Hope that helps, and let us know if you'd like a hand with the Entra-side SAML setup.