My company was planning to implement API Access Control. After enabling it we have ran into couple issues. Latest is that the "Is single sign-on enabled" permission has disappeared. We haven't used delegated SSO in a long time so it doesn't impact the SSO as such but we have kept is permission enabled for end user profiles to prevent password resets. Is there another way to prevent password resets for users based on profiles? For admins and some special cases we still want to have passwords so we can't disable password login on the org level.
Why can't these impacts be documented? It is really frustrating to discover these on trial and error basis. Like that also SOAP connections are impacted and apparently those cannot be authorized but you'd need to give "Use any API client" permission for the concerned user.
You are right actually, it is not enabling of API Access Control that had made the "Is Single Sign-on Enabled" permission to disappear but disabling of the "Disable login with Salesforce credentials". Someone who shouldn't had done this without asking/informing and coincidentally at the same time as we were testing API Access Control.