Allow Entra ID users without mailboxes to validate/activate Devolutions Hub accounts

Allow Entra ID users without mailboxes to validate/activate Devolutions Hub accounts

1 vote

avatar

Hello Devolutions team,

We would like to submit a feature request regarding user activation/validation in Devolutions Hub Business when using Microsoft Entra ID.

Summary
In our environment (Ville de Saguenay), we need to onboard a group of Entra ID users (about ~50) who do not have mailboxes and therefore cannot receive validation emails. Currently, after a period of time (we were told ~30 days), the user must validate their Devolutions account and an email is sent to complete the validation. This becomes a blocker for these users since they will never receive email.
Current behavior / problem

  • We can add Entra ID users to Hub Business and they can initially authenticate.
  • After the grace period, the platform requires a Devolutions account validation that relies on sending an email.
  • Users without mailboxes cannot complete this step, so they lose access / cannot access the Hub.


Why this matters

Many organizations have service accounts, kiosk/shared workstation users, or specific security contexts where identities exist in Entra ID but no email mailbox is provisioned. Requiring email-based validation prevents us from using Hub for these users and complicates enterprise onboarding.
Requested enhancement (options)
Any of the following would solve the issue (in order of preference):

  1. Admin validation/approval flow (no email required)
    • Allow a Hub admin to validate/activate a user account from the admin portal.
    • For example: “Pending validation” → Admin clicks “Validate/Activate”.
  2. Disable email validation requirement for Entra ID (SSO) tenants
    • If the user authenticates via Entra ID (OIDC/SAML), allow bypassing the Devolutions email validation requirement.
  3. Alternative validation method
    • Validate via an admin-generated one-time code shown in the Hub UI (not sent by email), or
    • Validate via another communication method configurable by the tenant (SMS, etc.).
  4. Tenant-level policy
    • A setting such as: “Require Devolutions email validation: On/Off”
    • Or “Require validation after X days: configurable/disable”.


Expected result

Users who authenticate successfully through Entra ID should be able to remain active and access Hub even if they do not have an email mailbox, using an admin-controlled validation method or an SSO-based validation approach.
If needed, we can provide additional details about our setup and use case

All Comments (1)

avatar

Hi @maximetremblay,

This seems to be a bug that was introduced recently. Users created via single sign-on with a validated domain should not be flagged for email verification.

We'll look into this.

Cheers,

Luc Fauvel