docs/content/security/for-admins/enforce-sign-in/_index.md

2.4 KiB
Raw Blame History

description toc_max keywords title aliases
Understand what happens when you force users to sign in to Docker Desktop 2 authentication, registry.json, configure, enforce sign-in, docker desktop, security, Enforce sign-in for Docker Desktop
/docker-hub/configure-sign-in/
/security/for-admins/configure-sign-in/

By default, members of your organization can use Docker Desktop without signing in. When users dont sign in as a member of your organization, they dont receive the benefits of your organizations subscription and they can circumvent Dockers security features for your organization.

There are multiple ways you can enforce sign-in, depending on your companies' set up and preferences:

How is sign-in enforced?

When Docker Desktop starts and it detects a registry key, a .plist file or registry.json file, the following occurs:

  • A Sign in required! prompt appears requiring the user to sign in as a member of your organization to use Docker Desktop. Enforce Sign-inPrompt
  • When a user signs in to an account that isnt a member of your organization, they are automatically signed out and cant use Docker Desktop. The user can select Sign in and try again.
  • When a user signs in to an account that is a member of your organization, they can use Docker Desktop.
  • When a user signs out, the Sign in required! prompt appears and they can no longer use Docker Desktop.

Enforce sign-in versus enforce SSO

Enforcing sign-in ensures that users are required to sign in to use Docker Desktop. If your organization is also using single sign-on (SSO), you can optionally enforce SSO. This means that your users must use SSO to sign in, instead of a username and password. When you enforce sign-in and enforce SSO, your users must sign in and must use SSO to do so. See Enforce SSO for details on how to enable this for your SSO connection. { .tip }