The login flow for IdP users accessing the Manager UI depends on the following two scenarios -
When only IdP access is specified
Only IdP access is allowed for IdP users to log into the Manager when either of the following is configured:
Allow IdP Access Only? checkbox is enabled on IdP Authentication page in the Manager
Or,
The
iv.core.IdP.access.onlycondition is set totrueinems.propertiesfile
In such a case, users are directly authenticated by the configured IdP on accessing the Manager (via https://<Manager IP> on a supported browser), instead of being presented with the standard Manager login screen. Authentication with IdP includes providing IdP credentials and MFA verification code generated by the virtual authenticator app, if MFA is enabled.
When only IdP access is not specified
If the Allow IdP Access Only? checkbox is disabled on IdP Authentication page in the Manager or, the iv.core.IdP.access.only condition is not set or set to false in the ems.properties file, the IdP users are presented with the IPS Manager login screen on accessing the Manager IP, where they can login using any of the following options:
Enter their username and password to log into the Manager as a local user
Or,
Choose to log into the Manager via IdP authentication (which includes IdP credentials and MFA verification code, if enabled).
.jpg)