# Dealing with unwanted (and probably spam) accounts via SSO?

**URL:** <https://meta.discourse.org/t/dealing-with-unwanted-and-probably-spam-accounts-via-sso/24050>\
**Category:** Feature\
**Tags:** sso, wordpress, discourseconnect\
**Created:** [2015年一月15日 19:47 UTC](https://meta.discourse.org/t/dealing-with-unwanted-and-probably-spam-accounts-via-sso/24050 "2015-01-15T19:47:52Z")\
**Posts on this page:** 1\
**Showing post:** 27

<div class="post-metadata">

**Author:** ![riking](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/riking/32/170938_2.png) [@riking](https://meta.discourse.org/u/riking)\
**Post date:** [2015年一月17日 04:56 UTC](https://meta.discourse.org/t/dealing-with-unwanted-and-probably-spam-accounts-via-sso/24050/27 "2015-01-17T04:56:56Z")

</div>

> [@molly\_cushing](#):
>
> new users have to register through our WordPress site.

Oh! This is important!

Discourse is assuming that **your Wordpress site is performing full vetting of all the accounts** before allowing them to sign on to the forum.

So all of the Discourse spam protections - blacklisted email domains, IPs, per-IP ratelimits, javascript-required two-click account activation, “per-IP user limit until one of them comes back on 15 different days” - are _effectively turned off_.

---

_[View the full topic](https://meta.discourse.org/t/dealing-with-unwanted-and-probably-spam-accounts-via-sso/24050)._
