Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,329
    • Merge requests 1,329
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #263661
Closed
Open
Issue created Oct 08, 2020 by Melissa Ushakov@mushakov🌻Developer0 of 6 checklist items completed0/6 checklist items

Provisioned Accounts - Allow setting "Project limit" and "Can create groups" attributes

Release notes

GitLab administrators will have the option to modify attributes for users provisioned by their group's SAML or SCIM integration. In this first iteration, administrators can reduce the risk of accidental exposure of their intellectual property by preventing their users from creating groups or projects outside of groups they are not already members of.

Problem to solve

Enterprise customers want more control over accounts in their group. See &4786 for more information.

Proposal

For accounts that are being provisioned using SAML JIT, give administrators the option to create users that can only create groups/projects within their top-level group. To achieve this, we can allow administrators to set users will have a "Project limit" value to 0 and "Can create groups" to false.

This setting will only be forward-looking and effective on users created after this setting is enabled. We will have a separate issue to apply these values to existing users.

Edited Dec 10, 2020 by Melissa Ushakov
Assignee
Assign to
Time tracking