The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Authentication flow for IdP users accessing the Manager

Prev Next

The login flow for IdP users accessing the Manager UI depends on the following two scenarios -

When only IdP access is specified

Only IdP access is allowed for IdP users to log into the Manager when either of the following is configured:

  • Allow IdP Access Only? checkbox is enabled on IdP Authentication page in the Manager

    Or,

  • The iv.core.IdP.access.only condition is set to true in ems.properties file

In such a case, users are directly authenticated by the configured IdP on accessing the Manager (via https://<Manager IP> on a supported browser), instead of being presented with the standard Manager login screen. Authentication with IdP includes providing IdP credentials and MFA verification code generated by the virtual authenticator app, if MFA is enabled.

When only IdP access is not specified

If the Allow IdP Access Only? checkbox is disabled on IdP Authentication page in the Manager or, the iv.core.IdP.access.only condition is not set or set to false in the ems.properties file, the IdP users are presented with the IPS Manager login screen on accessing the Manager IP, where they can login using any of the following options:

  • Enter their username and password to log into the Manager as a local user

    Or,

  • Choose to log into the Manager via IdP authentication (which includes IdP credentials and MFA verification code, if enabled).

M9-oktasignin-option-loginpage.jpg