šŸ” Email Verification Now Enabled for all SQC SAML SSO Users

:loudspeaker: Email verification is now required for all users logging in to SonarQube Cloud through SAML SSO. This one time only step adds a layer of security to help protect our service and user accounts.


:light_bulb: How does it work?
The next time you log in through SAML SSO, a verification modal will appear on SonarQube Cloud, prompting you to enter the code sent to your email.
Once the correct code is entered, you’ll proceed to access the product as usual — no impact on your experience beyond this one-time check.

Please reach out to us if you experience any issue

Thank you

Doesn’t Email validation per application in the enterprise defeats the very purpose of the organization’s SSO policy? In my organization, the elevated account used to access SonarQube cloud does not have an email Id tied to it. How do I bypass this step?

1 Like

Thank you for reaching out @bimalpn, @Joe shared your concerns and will follow up directly with you.

2 Likes

I don’t have email, I’m out of the system… But I’m MFA on it, why add an email verify?

Please, can I have the same follow up?

my org has also lost access to sonarcloud due to this change as we login via devops and even if they are legit azure tenant usernames, there are no email box, my colleague has already opened ticket with your support to hopefully get the email verification disabled only for our sc org or something else

1 Like

Hello @riccardomaccaferri — apologies for the delayed response.

Just to clarify: we have not enabled MFA on SQC. Instead, we introduced a one-time email verification step to address a security gap we identified.

Would it be possible for you to request a temporary mailbox just for the purpose of verifying your email? We understand this may be an inconvenience, and we’re actively working on less restrictive solutions. That said, we want to ensure security remains uncompromised.

Thanks for your understanding and patience.

To be transparent, we hadn’t anticipated that many customers would be using SQC without a valid email address and mailbox, especially since several core features depend on having both.

To better understand your use case and ensure we make more informed decisions moving forward, I’d appreciate it if you could book a time in my calendar so we can discuss it further.

1 Like

@anterokarttunen For users logging in through Azure DevOps, the process to unblock access by disabling email verification is outlined earlier in this thread. We are working on a long term solution.

1 Like

Hi Community,

I’m currently doing some research into this topic. I’d like to get on a call with customers who have been able to sign up/sign in to SonarQube Cloud with an email address that doesn’t have a mailbox behind it. We’re interested in understanding what the use case(s) are for customers setting their instance up this way.

Please sign up for a time on my schedule: https://calendar.app.google/RCydDs4wKSK7z3VW8

Best,

Tim Price
UX Research

1 Like