Controls GitHub sign-in authorisation and user access policies
for this tenant.
Settings
- Enabled
- Activates GitHub sign-in for this tenant. WARNING: Ensure you have configured
suitable constraints below in Allowed Organizations and/or Allow Repositories before enabling this option. If you
enable without any constraints then any GitHub user will be able to sign-in to your tenant.
- Allowed Organizations
-
Only members of these GitHub organisations may sign in. Enter GitHub
organisation names (e.g.
my-org
). At least one organisation is required.
The
GitHub OAuth App must request the
read:org
scope to verify organisation membership.
- Allowed Repositories
-
Optional. Further restrict access to users who have access to
specific repositories within the allowed organisations. Enter
repository names in
org/repo
format.
- Excluded Identities
- GitHub email addresses that should never be
allowed to sign in, even if they are members of an allowed
organisation.
Users authenticate with
their personal GitHub account. Membership in the allowed organisations
is checked at every login. If a user is removed from an organisation
they will immediately lose access.