Restrict apps to specific SSO groups
AppsApps shared via SSO authentication can now be limited to specific groups from your identity provider. In the Share panel, select Via SSO authentication, turn on Restrict to specific SSO groups, and add the group names that should have access. Visitors outside those groups can't open the app.
To get started, an admin turns on SSO-group-based app access in Authentication settings and enters the attribute that carries group names from the identity provider. Apps have their own group attribute, separate from pages, and tenant owners can always open every app.
Learn more about SSO-group-based access and app access control.