ANS-1475 · ROLES, PERMISSIONS & SECURITY

Why is SAML Login Not Available for the NetSuite Administrator Role?

NetSuite's robust security measures, including mandatory Two-Factor Authentication, inherently restrict SAML login for the Administrator role.

Short answer

NetSuite explicitly prohibits SAML (Security Assertion Markup Language) login for the Administrator role. This is a fundamental security measure to protect critical system access. Instead, the Administrator role is subject to mandatory Two-Factor Authentication (2FA), ensuring a higher level of account security.

Scenario

Users attempting to configure SAML (Security Assertion Markup Language) for single sign-on (SSO) within NetSuite may encounter limitations when trying to apply this authentication method to the Administrator role. This situation typically arises when an organization seeks to streamline login processes for all users, including those with the highest level of system access.

Solution

NetSuite's security architecture is designed to prevent SAML login for the Administrator role. This policy is in place to safeguard the most privileged access within the system from potential single sign-on vulnerabilities. Consequently, the Administrator role is instead subject to mandatory Two-Factor Authentication (2FA), which provides an additional layer of security beyond standard password authentication.

Expert NetSuite Support

Need help with this NetSuite issue?

Roles, Permissions & Security consulting and configuration support

Talk to a consultant