Skip to main content

此版本的 GitHub Enterprise Server 将于以下日期停止服务 2026-03-17. 即使针对重大安全问题,也不会发布补丁。 为了获得更好的性能、更高的安全性和新功能,请升级到最新版本的 GitHub Enterprise。 如需升级帮助,请联系 GitHub Enterprise 支持

查看和管理用户对企业的 SAML 访问

你可以查看和撤销企业成员的活动的 SAML 会话。

谁可以使用此功能?

Enterprise owners

Instances that have configured SCIM provisioning

About SAML access to your enterprise account

When you enable SAML single sign-on for your enterprise account, each enterprise member can link their external identity on your identity provider (IdP) to their existing account on your GitHub Enterprise Server instance. To access each organization's resources on GitHub, the member must have an active SAML session in their browser. Enterprise owners can view and revoke a member's active SAML sessions at any time.

注意

This view is only enabled when SAML with SCIM is enabled.

Viewing a linked identity

You can view the single sign-on identity that a member has linked to their account on GitHub.

  1. In the top-right corner of GitHub Enterprise Server, click your profile picture, then click Enterprise settings.

  2. On the left side of the page, in the enterprise account sidebar, click People.

  3. Click on the name of the member whose linked identity you'd like to view or revoke.

  4. In the left sidebar, click SAML identity linked.

    Screenshot of the people summary for @octocat. A link, labeled "SAML identity linked", is highlighted with an orange outline.

  5. Under "Linked SSO identity", view the linked SSO identity for the member.

The identity data on this page will include the SCIM data that was sent to GitHub during user provisioning. This SCIM data is what GitHub uses when matching a SAML SSO request to the provisioned user. Note that GitHub does not use SAML mappings when SCIM is enabled. For more information on how GitHub maps SAML and SCIM data for users, please see REST API endpoints for SCIM.

Viewing and revoking an active SAML session

  1. In the top-right corner of GitHub Enterprise Server, click your profile picture, then click Enterprise settings.

  2. On the left side of the page, in the enterprise account sidebar, click People.

  3. Click on the name of the member whose SAML session you'd like to view or revoke.

  4. In the left sidebar, click SAML identity linked.

    Screenshot of the people summary for @octocat. A link, labeled "SAML identity linked", is highlighted with an orange outline.

  5. Under "Active SAML sessions", view the active SAML sessions for the member.

  6. To revoke a session, to the right of the session you'd like to revoke, click Revoke.