The Manager and Central Manager now enable Identity Provider (IdP) users to authenticate and log into the Manager UI using the OpenID Connect (OIDC) authentication protocol. Built on the OAuth 2.0 framework, the primary functions of OIDC are to authenticate users, confirm their identity, and enable clients to retrieve basic user information from an IdP.
IdP authentication in Manager aims to enhance security and optimizes user login experience using OIDC-based Single Sign-On (SSO) mechanism. With OIDC support, users can access the Manager by using IdP authentication, a process that can include Multi-Factor Authentication (MFA). Supported IdPs in the Manager include Okta, Microsoft Entra, and Google IdP.
Note
This feature is supported in Manager running on 11.1 Minor 9 version or higher.
Pre-requisites of using IdP authentication in the Manager
The user must have an account created with the IdP, which they will be using to log into the Manager via IdP authentication method. The user must also have IPS Manager client application, appropriate user profile and user policy created and assigned to them by their IdP system administrator so that they can access the Manager using IdP credentials.
IPS Manager client application must be registered with the IdP.
Note
You need to have access to IdP with required privileges to register the IPS Manager client application. Or else, contact your IdP system administrator and request for the registration.
During the Manager client application registration process, the IdP system administrator must configure the Redirect URL as the Manager IP (that is, https://<Manager IP>). To override the default Redirect URL, the following property needs to be added in the <
Manager_Install_Dir>\config\ems.propertiesfile:iv.core.idpRedirectURL.link=<Manager IP>.A proxy server should be configured in the Manager for internet connectivity.
Configuring IdP authentication in the Manager
This process includes the following two steps:
Configuring and adding the IdP server(s) in the Manager with required details using the IdP Authentication page. For more information, see Configure IdP servers.
Adding a user with Authentication Type as OIDC and user role with required permissions to log in and access IPS Manager using IdP credentials. The user must also have an account in IPS Manager configured with the same email address as used in the IdP. For more information, see Add a user role.