🚀 New: Opt-In Strict Enterprise Governance and SSO Enforcement in SonarQube Cloud Enterprise!

Hello everyone,

We’re excited to announce that opt-in strict enterprise governance and SSO enforcement controls are now available in SonarQube Cloud Enterprise!

Following the recent release of Domain Verification and the Breakglass Mechanism, these new capabilities provide enterprise administrators with the essential controls needed to eliminate unapproved organization creation and clean up fragmented identities. This allows security and admin teams to ensure all company code and user activity stay strictly within your designated Enterprise boundary.

What’s new?

  • Centralized Organization Control: Block any user authenticating via your Enterprise SSO—or using an email matching your verified corporate domains—from creating new SonarQube Cloud organizations outside of your Enterprise.

  • Strict SSO Identity Enforcement: Eliminate alternate login paths. Once activated, SonarQube Cloud blocks logins and Personal Access Token usage via parallel DevOps accounts (like independent GitHub or GitLab authentications) for users on your validated domains, routing logins through your centralized SSO Identity Provider.

  • Opt-In per Verified Domain: These governance rules are completely opt-in, allowing you to turn them on exactly when you are ready.

Where to find it

Because these policies apply to your corporate identity, you must first verify your domain.

  1. Navigate to your Enterprise’s Administration settings and head to the SSO & Provisioning tab.

  2. Complete the Single sign-on and Domain Verification steps in the setup wizard.

  3. Once your domain is successfully verified, you will see the option to toggle on these new enterprise governance and SSO enforcement controls.

Image - Restrict Organization creation outside of the Enterprise

Image - Block logins and PAT usage via DevOps accounts

For a complete step-by-step setup guide, check out our official documentation.

We’d love to hear your thoughts on these new governance capabilities and how they fit into your security rollout plans. Share your feedback in the comments!

— Chris

3 Likes