Auth0 SAML Users Are Required to Verify Their Email

Overview

Auth0 SAML and Ping enterprise connections do not include a setting to always verify user email addresses, requiring the Identity Provider (IdP) to include the verification status in the SAML response. When this status is missing, Auth0 prompts users to verify their emails and restricts functionality. 

Applies To

  • SAML
  • Email Verification

Cause

Enterprise connections, except for Active Directory (AD) and Active Directory Federation Services (ADFS), do not include an email verification toggle. Auth0 requires the IdP to provide the email_verified status directly.

Solution

How is the email verification status resolved for SAML connections?

Configure the IdP to return the email_verified status within the SAML response to prevent Auth0 from generating email verification prompts. Auth0 requires the IdP to provide the verification status directly for all enterprise connections, except for AD and ADFS.

Recommended content

No recommended content found...