Request: Allow IDP Impersonation to Be Assigned to a Group
J
Jonathan Sebastian Guasch
Currently, IDP Impersonation can only be assigned to individual users who are members of the Account Admin team. This creates a limitation for organizations that have dedicated IDP Admins who are responsible for troubleshooting identity and user-related issues but are not part of the Account Admin team.
Our IDP Admins often need the ability to impersonate users for troubleshooting purposes, such as reproducing user-specific issues, validating configurations, investigating authentication problems, and confirming the user experience. However, requiring these administrators to be added to the Account Admin team in order to gain impersonation access can provide broader permissions than are necessary for their role.
Our Ask
We would like IDP Impersonation to support group-based assignment rather than restricting the capability to the Account Admin team.
For example, administrators could be granted impersonation privileges by adding them to a designated group such as IDP Support Admins or User Troubleshooting Admins. Anyone who is a member of that group would then have the appropriate impersonation capability without needing to be granted full Account Admin access.
Benefits
Supporting group-based assignment would:
Provide greater flexibility in managing impersonation permissions.
Allow IDP Admins and support teams to troubleshoot users without requiring Account Admin privileges.
Follow the principle of least privilege by granting only the permissions necessary for troubleshooting.
Make access management easier by allowing organizations to manage permissions through existing groups.
Reduce the need to add users to the Account Admin team solely to provide impersonation capabilities.
Make it easier to onboard or remove administrators as team responsibilities change.
Overall, our request is to allow IDP Impersonation to be assigned to a specific group, giving organizations more granular control over who can impersonate users while avoiding the need to grant full Account Admin access.