Organization Owner removed from group on each SSO login

Hello,
This is a SonarQube Cloud, Enterprise (private) administration question.
I have a user who will not stay in the Owners group for our organization - they are placed there, but get removed every time they log in via SSO. Other members of Owners group do not have this problem.

We recently set up SAML SSO, replacing our login via Azure Devops.
This creates new users. I used my old admin user to assign enterprise and org permissions to my new SSO user. I then assigned permissions to the other members of the team who will administer SonarCloud, and to our Billing administrator.

The Billing administrator is in Enterprise Administrators.
They can be added to Owners group, which has permissions to Administer Organization. But the Billing administrator gets removed from Owners on every SSO login.

I don’t know how to reproduce the failure, because other team members seem to stay in Owners after logging in.

The work-around is to give the Billing administrator’s user Administer Organization permissions at the org user level, and not just depend on inheriting from Owners group.

Thank you

Hi,

Welcome to the community!

Groups are synchronized from your IdP. Is the user in question a member of the “Owners” group in the IdP?

 
Ann