Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: Published by Scroll Versions from space IDS and version 8.3

This page introduces basic tasks that the System Administrator needs to carry out in order to use Ubisecure SSO and its services.

...

Mapping Authenticated User to Directory User – Steps to Consider

  1. Is there a common attribute between the authentication provider and the directory user?
    1. If not
      1. Use user driven federation (Ubisecure SSO User Driven Federation - documentation)
      2. Use RESTServiceUserMapping / JSONServiceUserMapping to use a backend service to convert one ID to another
      3. Use basic user mapping to manually manage (Management UI Mappings - SSO)
      4. Use custom attributes to all admin or user to manage a common attribute and use that for mapping
    2. If so
      1. Is the attribute already in the correct format when received from the method?
        1. If not → Use method attribute mapping to make the format match the directory user attributes (Management UI Attribute Mappings - SSO)
  2. Configure directory user mapping
    1. Activate for each method
  3. Configure authorization policy