- 필수 기능
- 시작하기
- Glossary
- 표준 속성
- Guides
- Agent
- 통합
- 개방형텔레메트리
- 개발자
- Administrator's Guide
- API
- Datadog Mobile App
- CoScreen
- Cloudcraft
- 앱 내
- 서비스 관리
- 인프라스트럭처
- 애플리케이션 성능
- APM
- Continuous Profiler
- 스팬 시각화
- 데이터 스트림 모니터링
- 데이터 작업 모니터링
- 디지털 경험
- 소프트웨어 제공
- 보안
- AI Observability
- 로그 관리
- 관리
",t};e.buildCustomizationMenuUi=t;function n(e){let t='
",t}function s(e){let n=e.filter.currentValue||e.filter.defaultValue,t='${e.filter.label}
`,e.filter.options.forEach(s=>{let o=s.id===n;t+=``}),t+="${e.filter.label}
`,t+=`Set up the gitlab integration.
Detects when SAML Single Sign-On (SSO) enforcement is disabled for a GitLab group. Disabling SSO enforcement removes authentication controls and may indicate unauthorized access or persistence attempts.
This rule monitors GitLab audit events for true
to false
configuration changes related to SSO, specifically “Group SAML SSO configuration changed: enforced_sso changed from true to false”. SAML SSO enforcement ensures group members authenticate through the organization’s identity provider before accessing GitLab resources. When this enforcement is disabled, users can potentially bypass centralized authentication controls, creating security gaps that attackers may exploit for persistence or to maintain access after initial compromise.
{{@usr.name}}
has legitimate administrative authority to modify SAML SSO settings for the affected GitLab group.