This is generally done by using the domain configuration. For example, all users with an email address domain of can be configured to use a particular SAML or OpenID Connect configuration.

As soon as you configure one IdP with a domain, the login panel will collect the email address first to understand if we need to ask for a password or forward them along to a federated identity provider.

