Important
Configuring the IdP server is the first step of configuring IdP authentication in the Manager. After the required IdP server details have been added in the Manager, a user role with required authentication type and permissions must be created to complete the configuration process.
You can configure multiple IdP servers in the Manager and the Central Manager for authentication purposes. Use the following navigation paths to configure the IdP servers:
In Manager: Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication
In Central Manager: Manager → Setup → GUI Access → IdP Authentication
.jpg)
Callout | Description |
|---|---|
1 | Grid view |
2 | Bottom menu |
The following options are available in the IdP Authentication page:
Options | Description |
|---|---|
Grid view | |
Allow IdP Access Only? | Enabling this checkbox allows IdP users to access the Manager UI using IdP authentication mechanism only. In such a case, the user is taken directly to IdP authentication page when they access the Manager login URL. For more information, see Authentication flow for IdP users accessing the Manager. |
Order of Consideration | The numbers depict the order in which IdP servers are prioritized for authentication. The first server is considered the primary server to be used for authentication. You can use the |
IdP Name | The name of the IdP server. IdP Name is used for the unique identification of the IdP server configuration and is displayed in the Manager login page. |
IdP Domain | Displays the IdP domain name configured |
Enabled | Displays the status of the configured servers
|
Open Id Configuration URL | Shows the Open ID configuration URL (that is the discovery URL for OIDC protocol provided by IdP) |
Client Id | Shows the Client ID configured for the selected server
|
Client Secret | Shows the client secret key to be used for the server configuration
|
Last Connection Test | Shows the date and time of the last connectivity test to the selected server |
Comment | Shows comments (if any) |
Bottom menu | |
| Click this icon to add an IdP server. |
| Click this icon to delete an IdP server. |
Test Connection | Click to test whether the connection with the selected IdP server is working fine. If the connection is successful, a message is displayed for the same. |
| Use these arrows to update the order of IdP servers. When done, click Save. |
Click a column header and select the option to sort based on ascending or descending order. The options are Sort Ascending and Sort Descending. The column based on which the list is sorted is indicated in the column header by an up arrow icon for ascending order and down arrow icon for descending order.
Add an IdP server
Pre-requisites:
Make sure that you have an account created with required Identity Provider (IdP), which you will be using to log into the Manager via IdP authentication. You must also have appropriate user profile and policy created and assigned to your account by the IdP system administrator.
Ensure that you have a proxy server configured in Manager and have the following details handy: IdP Domain, Open Id Configuration URL, Client Id and Client Secret.
To add an IdP server in the Manager -
Navigate to the Manager → <Admin Domain Name> → Setup → GUI Access → IdP Authentication page.
IdP Servers page is displayed.
Click
.Edit IDP Server window is displayed.
.jpg)
Enter details for the following fields:
Field
Description
Enable?
Check the box to enable the IdP server being configured.
IdP Name
Enter the name of the IdP server.
IdP Domain
Enter the IdP domain name.
Open Id Configuration URL
Enter the Open ID configuration URL associated with the IdP server being configured.
Client Id
Enter the Client ID for the selected IdP server.
Client Secret
Enter the client secret key to be used for the server configuration.
Comment
(Optional) Enter comments, if any.
Click Test Connection to verify that the Manager can connect to the IdP server.
Click Save to save the configuration.
The IdP server details is displayed in the IdP Authentication page
Edit an IdP server
In the IdP Authentication page in the Manager, double click any server you want to edit.
You can either enable or disable the IdP server. You can also change other configuration details, if required.
Click Save.
Delete an IdP server
In the IdP Authentication page in the Manager, select any server you want to delete and click
.png)
Click OK in the confirmation page to delete the IdP server.
The IdP server is deleted.
Click Save.
.jpg)
.jpg)
.jpg)
.jpg)