Understanding SSO and password behaviors
Who is this article for?
Ideagen EHSQ Enterprise or Decani Administrators and Module Developers who manage Single Sign-On (SSO) behavior.
Appropriate administrative permissions required.
For Subscribers that require SSO, you do not need to configure individual user behavior unless you want to allow specific users to sign in with a username and password. The SSO setting in Admin Preferences determines whether SSO is required or optional for the Subscriber, see Configuring Single Sign-On (SSO).
Login behavior
Login Behaviors specify how an individual user signs in. This setting can:
- Require a user to sign in with SSO
- Allow a user to sign in with a username and password, even when SSO is available
- Require a user to use sign in from an assigned Identity Provider (IdP)
IdP override
When an IdP authentication is required the login behavior requires verification from a requested Identity Provider (IdP) endpoint URL. The Identity Provider (IdP) endpoint is found within the customer’s security domain. This address does not need to be reachable from the public Internet or from Ideagen servers, but the user’s web browser will need to have access to it directly, by VPN, or by another secure network.
Mobile behavior
The mobile login behavior must align with the systems login settings. The mobile application communicates with the server through RESTConnect, and the settings described above will also authenticate the RESTConnect mobile login behavior.