Approve new devices via SAML SSO instead of the backup password
This is about Proton Pass for Business.
When SSO via SAML is enabled, users still have to set up a Proton backup password for their account. They almost never need it, because they sign in via SAML. The only time it's required is when a user signs in on a new device: they then have to enter the backup password on an already signed-in device to approve the new one.
Since SAML SSO is the main way our users sign in, the backup password is confusing for business users, and many of them forget it because they rarely or almost never use it.
Suggestion: Allow new devices to be approved through the SAML authentication flow. The user would be prompted to re-authenticate via SAML SSO on the existing device to approve the new device. Since the existing device already holds the encryption keys, the SAML re-authentication would only serve to verify the user's identity. The backup password would no longer be needed for this step.
Ideally, admins could enable this as an organization-wide policy.