Prerequisites
Before specifying single sign-on (SSO) settings on the TMEMS administrator console, configure the identity provider you choose for SSO (AD FS 4.0, Azure AD, or Okta).
Refer to the following articles for information:
Enabling SSO
- Go to Administration > Administrator Management > Logon Methods.
Click the image to enlarge.
- In the Single Sign-On section, click the toggle button to enable SSO.
Click the image to enlarge.
- Click Add to create an SSO profile.
Click the image to enlarge.
- Configure general information for SSO.
- Profile Name: specify the SSO profile name
- Unique Identifier: provide the identifier that is globally unique to your site.
If you have to change the unique identifier due to conflict with another identifier, make sure you also change it in your identity provider configuration.
- Administrator Console: automatically generated upon adding the Unique Identifier
Click the image to enlarge.
- Select the subaccounts to which the current profile applies:
- All subaccounts: applies this profile to all subaccounts.
You can create only one profile that is applied to all subaccounts.
Click the image to enlarge.
- Specified subaccounts: applies this profile to specified subaccounts.
Select subaccounts from the Available pane and click Add > to add them to the Selected pane.Click the image to enlarge.
- All subaccounts: applies this profile to all subaccounts.
- Complete identity provider configuration for SSO.
- Select your identity provider from the Identity provider drop-down list.
- Specify the logon and logoff URLs for your identity provider.
(For Okta only) Click Download Logoff Certificate to obtain the certificate file to upload to your federation server.Use the logon URL collected from AD FS, Azure AD or Okta configurations.
The logoff URL logs you off and also terminates the current identity provider logon session.
- Locate the certificate file you downloaded from AD FS, Azure AD or Okta configurations and upload it for signature validation.
- Specify the identity claim type based on the claim you configured for AD FS, Azure AD or Okta (e.g. if you use email as the claim name, type email).
Click the image to enlarge.
- Click Save to save the profile.
- Click Save to save SSO settings.