Request for Single Sign-on and/or UPN sign-on
Ideally, we'd like to be able to use single sign on to authenticate users into the portal.
Best Answer
-
Geoff_Ross Cireson Consultant O.G.Hi Keith,
This is totally possible. The KA for portal install on the Cireson Support Portal has full details but you can pick this option when installing the portal. The only caveat is that the portal server must be a SCSM Management Server to avoid a double hop authentication process.
Let me know if you need more info.
Geoff
5
Answers
This is totally possible. The KA for portal install on the Cireson Support Portal has full details but you can pick this option when installing the portal. The only caveat is that the portal server must be a SCSM Management Server to avoid a double hop authentication process.
Let me know if you need more info.
Geoff
Also for UPN options we have this open in another feature request which you can vote on below:
https://community.cireson.com/discussion/84/allow-for-portal-authentication-via-users-upn-or-e-mail-address-rather-than-samaccountname
Will convert this from a feature request thread to a question
Cheers
Joe
Thanks for the link for the UPN option Joe, I had searched, but I couldn't find one. I'll upvote that one. On a side note, I was told that even if one existed to open another, to show more interest for the feature.
So, apologies, this is my fault for not elaborating. I'm talking about single sign on, as in I have an ADFS proxy that I authenticate with, and it uses win auth/SPNs to authenticate to other things for me. So my users can sign in once, and then they have a token to authenticate to many things. Then when users start their day, and they open up the portal, the service desk, and whatever else they don't have to retype their username and password several times, it asks once and then they authenticate using their token. When I asked support, their response was "Currently ADFS is not supported - there are web.config hacks I'm aware of to make this work but no supported methods at this stage. Regards." If anyone knows of one of these hacks, I could give it a go, in either case, can this be moved back to Feature Requests until it's officially supported?
Great stuff! The more up-votes for a feature the better and helps us determine demand, we do understand duplicates will still come through if features cannot be found so these will be tagged as duplicates with a URL to the original feature request.
@Jan_Vidar_Elven has some great info in the below thread which may help you with ADFS:
https://community.cireson.com/discussion/211/any-way-to-use-adfs-to-authenticate-to-cireson-portal
I have opened a feature request on your behalf for ADFS support on the below thread
https://community.cireson.com/discussion/508/adfs-options-for-the-portal
Cheers
Joe