Org not enforced when app is configured for business users

I have an app configured for business users. I tried logging in without providing the org name or id. Instead of rejecting the request, its routing me to SSO configured on my domain.