The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Configure IdP servers in the Manager

Prev Next

Important

Configuring the IdP server is the first step of configuring IdP authentication in the Manager. After the required IdP server details have been added in the Manager, a user role with required authentication type and permissions must be created to complete the configuration process.

You can configure multiple IdP servers in the Manager and the Central Manager for authentication purposes. Use the following navigation paths to configure the IdP servers:

  • In Manager: Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication

  • In Central Manager: Manager → Setup → GUI Access → IdP Authentication

IdP server configuration page
IdP server configuration page


Callout

Description

1

Grid view

2

Bottom menu

The following options are available in the IdP Authentication page:

Options

Description

Grid view

Allow IdP Access Only?

Enabling this checkbox allows IdP users to access the Manager UI using IdP authentication mechanism only. In such a case, the user is taken directly to IdP authentication page when they access the Manager login URL. For more information, see Authentication flow for IdP users accessing the Manager.

Order of Consideration

The numbers depict the order in which IdP servers are prioritized for authentication. The first server is considered the primary server to be used for authentication.

You can use the arrow_down.jpg and arrow_up.jpg to make changes in the order and click Save.

IdP Name

The name of the IdP server. IdP Name is used for the unique identification of the IdP server configuration and is displayed in the Manager login page.

IdP Domain

Displays the IdP domain name configured

Enabled

Displays the status of the configured servers

  • tick.jpg means the configured server is enabled for authentication purpose.

  • cross.jpg means the server is configured but disabled.

Open Id Configuration URL

Shows the Open ID configuration URL (that is the discovery URL for OIDC protocol provided by IdP)

Client Id

Shows the Client ID configured for the selected server

Note

The Client ID is obtained when the IPS Manager client application is registered with the IdP.

Client Secret

Shows the client secret key to be used for the server configuration

Note

The Client secret key is obtained when the IPS Manager client application is registered with the IdP.

Last Connection Test

Shows the date and time of the last connectivity test to the selected server

Comment

Shows comments (if any)

Bottom menu

GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png

Click this icon to add an IdP server.

GUID-B13A6E00-0610-4794-A2FF-1EE7614AD1D3-low.png

Click this icon to delete an IdP server.

Test Connection

Click to test whether the connection with the selected IdP server is working fine. If the connection is successful, a message is displayed for the same.

arrow_down.jpg and arrow_up.jpg

Use these arrows to update the order of IdP servers. When done, click Save.

Click a column header and select the option to sort based on ascending or descending order. The options are Sort Ascending and Sort Descending. The column based on which the list is sorted is indicated in the column header by an up arrow icon for ascending order and down arrow icon for descending order.

Add an IdP server

Pre-requisites:

  • Make sure that you have an account created with required Identity Provider (IdP), which you will be using to log into the Manager via IdP authentication. You must also have appropriate user profile and policy created and assigned to your account by the IdP system administrator.

  • Ensure that you have a proxy server configured in Manager and have the following details handy: IdP Domain, Open Id Configuration URL, Client Id and Client Secret.

To add an IdP server in the Manager -

  1. Navigate to the Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication page.

    IdP Servers page is displayed.

  2. Click GUID-E7BA235E-C8E9-494B-A481-32F301FEAAB8-low.png.

    Edit IDP Server window is displayed.

    111M9-edit-idp-server-window.jpg
  3. Enter details for the following fields:

    Field

    Description

    Enable?

    Check the box to enable the IdP server being configured.

    IdP Name

    Enter the name of the IdP server.

    IdP Domain

    Enter the IdP domain name.

    Open Id Configuration URL

    Enter the Open ID configuration URL associated with the IdP server being configured.

    Client Id

    Enter the Client ID for the selected IdP server.

    Client Secret

    Enter the client secret key to be used for the server configuration.

    Comment

    (Optional) Enter comments, if any.

  4. Click Test Connection to verify that the Manager can connect to the IdP server.

  5. Click Save to save the configuration.

    The IdP server details is displayed in the IdP Authentication page

Edit an IdP server

  1. In the IdP Authentication page in the Manager, double click any server you want to edit.

  2. You can either enable or disable the IdP server. You can also change other configuration details, if required.

  3. Click Save.

Delete an IdP server

  1. In the IdP Authentication page in the Manager, select any server you want to delete and click

    GUID-B13A6E00-0610-4794-A2FF-1EE7614AD1D3-low.png
  2. Click OK in the confirmation page to delete the IdP server.

    The IdP server is deleted.

  3. Click Save.