Skip to Main Content
IBM Data Platform Ideas Portal for Customers


This portal is to open public enhancement requests against products and services offered by the IBM Data Platform organization. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).


Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:


Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,


Post your ideas

Post ideas and requests to enhance a product or service. Take a look at ideas others have posted and upvote them if they matter to you,

  1. Post an idea

  2. Upvote ideas that matter most to you

  3. Get feedback from the IBM team to refine your idea


Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

IBM Employees should enter Ideas at https://ideas.ibm.com



Status Under review
Created by Guest
Created on Jun 24, 2026

Platform Administration - Restrict local user creation through API

Administrators need a platform-level control to restrict or prevent local user creation through API or CLI tooling when the user is intended to be managed by a configured SAML identity provider.

While testing CPDCTL functionality, it was identified that a user can be created through the CLI and then appear in the Cloud Pak for Data platform as a SAML provider user. This behavior may allow user records to be created outside the intended identity provider workflow, bypassing the expected process where SAML-authenticated users are introduced to the platform only through the configured identity provider and approved SSO flow.

The requested enhancement is to provide a supported administrative control that prevents or restricts the creation of SAML provider users through CLI-based or API-based user creation unless the action is explicitly authorized and validated by platform policy.

Ideally, user creation for SAML-authenticated accounts should be controlled exclusively through the configured identity provider, or governed by platform-level validation that ensures users cannot be created outside the intended SSO process.

Requested capabilities include:

  • Prevent creation of SAML provider users through CPDCTL, API, or other CLI-based user-management methods.

  • Provide an administrative setting to enforce SSO-first-login-only user creation.

  • Ensure SAML-authenticated users can only be created or activated after successful authentication through the configured identity provider.

  • Add platform validation to prevent CLI or API creation of users that are associated with a SAML identity provider unless explicitly permitted.

  • Provide role-based controls to determine who, if anyone, can create users outside the identity provider flow.

  • Add audit logging for user creation events that identifies whether the user was created through SSO, UI, API, CLI, or another mechanism.

  • Provide reporting or administrative visibility into users created outside the SAML SSO workflow.

  • Optionally provide a policy setting to block user creation methods that do not originate from the configured identity provider.

There is currently no hard workaround to enforce “SSO first login only” as the exclusive method for creating a user entry in CPD. The only available mitigations are to limit user-management authority to the smallest possible administrator scope and periodically review CPD users against the identity provider list to identify and remove accounts that were created outside the intended SSO flow.

This enhancement is needed to improve platform administration, identity governance, and access control. Organizations that rely on SAML-based SSO need assurance that platform users are created only through the authorized identity provider workflow and not through alternate CLI or API paths. Without this control, administrators must rely on manual reviews and after-the-fact cleanup, which introduces operational overhead and potential governance risk.

Providing a platform-level restriction for SAML provider user creation would help ensure that CPD user management remains aligned with enterprise identity provider policies, reduce the risk of unauthorized or unintended account creation, and strengthen administrative control over identity lifecycle management.

Needed By Week