Best Practice for Desktop Simplified Sign-On
Enable 'Desktop Simplified Sign-On' for your repository.

Edit a user and check 'Allow Desktop Simplified Sign-On for this user'.
Enter a 'Windows domain user' if known, otherwise enter a new password for the user and 'Windows domain user' will be filled in automatically upon their first login.

Desktop Login
If enabled for a user when they start their Hubble Desktop then the User and Password fields are auto-filled.

Best Practice for Users using Web and Desktop
Once Hubble and the Identity Provider (IdP) have been configured, see:
- Configure Hubble Single Sign-on with SAML 2.0
- SSO Identity Provider (Idp) Integration Supplementary detail
the IdP will handle authentication and will pass the user's email address to Hubble in an encrypted token.
This email address should exactly match that configured for the user in the Hubble Administration tool.

Best Practice for Disabling Users in Hubble and an IDP
If Hubble is configured for single sign-on and a user is subsequently disabled in Hubble using the Administration tool, the Hubble user experience can be improved by disabling the user in the IDP as well as in Hubble. Otherwise the user can still log in to Hubble using SSO and may be able to navigate for a short while, before a message appears saying that their account has been disabled.