Users with the SP administrator role can use the Authentication page to modify the authentication method for service provider and tenant users.
To modify the authentication method:
The Authentication page appears.
The Authentication Type page appears.
Local Authentication
Authentication with SSO Server
Authentication and Authorization with SSO Server
For more information about authentication methods, see Authentication Methods Overview.
Table 145: Fields on the Authentication Type Page
Field | Description |
---|---|
SSO Server | Select the SSO server name from the list. |
SSO Initiated By | Select the SSO initiation method.
|
If you select the Service Provider (CSO) method, then the following field is displayed: | |
Username Pattern | Enter a list of username patterns separated by a comma, space, or semicolon. For example, *@aaa-example.com; *@xyz-example.com. Note: If the username matches the username pattern, the user is redirected to the SSO server to complete the authentication process. If the username does not match with any of the username patterns, then the local authentication is assumed. |
When you select Identity Provider (SSO Server) method, the following fields are displayed: | |
Direct CSO Login Message | Enter the message to display when a user tries to directly access CSO without being authenticated by the SSO server. |
Logout Message | Enter the message to be displayed when the user logs out from CSO. |
Tenant Identifier | Select the identifier to correlate the tenant Security Assertion Markup Language (SAML) attribute with the tenant. Whenever the tenant is onboarded into the system, the tenant is uniquely identified by any one of the following identifiers:
|
Permitted Roles and Mapping | Roles used in the SSO server (external system) are different from the roles used in CSO. Therefore, you must map the roles defined in CSO with the roles defined in the external SSO server (Identity Provider). To map the roles:
You can also modify the permitted role and delete one or more permitted roles. |
Note If you select the Local Authentication type, the SSO Server, SSO Initiated By, and Username Pattern fields are not displayed.