What happens when your identity provider is down while SSO is required, and how Cargo Marshal support restores access.
When Require SSO is on, people on your domain can only sign in through your identity provider. If the identity provider is down or misconfigured, nobody on the domain can sign in, including your owners and admins. There is no owner exemption: an exemption would be a password path that bypasses your identity provider's controls.
Contact Cargo Marshal support from an address on your verified domain and name your organization. Support turns Require SSO off for you. Password and social sign-in then work again for your domain until you turn it back on in Settings → Single sign-on.
Members who still have a session stay signed in for its lifetime, so someone on your team may still be able to turn the setting off themselves.
Every impersonation is recorded in the server log with the impersonating admin and the target user.
Deleting the SSO connection also lifts the requirement, but it removes the domain verification and the link between members and their identity provider accounts. Prefer turning the requirement off.