The EmpowerID SSO Connector framework allows you to configure an Identity Provider connection for Windows Authentication to allow your users the ability to log in to EmpowerID using their Windows credentials.
For users to log in to EmpowerID using their Windows credentials, they must have user accounts either in the domain being protected by EmpowerID or in a domain trusted by that domain.
This topic describes how to configure an SSO connection for Windows Authentication and is divided into the following activities:
Configuring an SSO connection for Windows Authentication
Testing the SSO connection
To configure the SSO Connection for Windows Authentication
From the Navigation Sidebar of the EmpowerID Web interface, navigate to theSAML Connectionsmanagement page by expandingAdmin > Applications and Directories > SSO Connectionsand clickingSAML.
From theSAML Connectionstab of SAML SSO Manager, search forWindows.
From the SAML Connections grid, click the drop-down arrow for theLogin Using Windowsrecord and clickEdit.
From theGeneraltab of theConnection Detailspage that appears, do the following:
Optionally, if you are using multi-factor authentication and you want to edit the default MFA Point Value for Windows auth, scroll to theConnection Detailssection and type a new value in theMFA Point Valuefield.
Scroll to theAccount Informationsection and select the directory for your AD domain from theAccount Directorydrop-down.
Optionally, scroll to theSingle Logout Configurationsection and enter a logout URL in theLogout URLfield.
Leave all other fields as is.
Click theDomainstab at the top of the page and then click theAdd (+)button in theAssigned Domainssection.
In theAdd Domaindialog that appears, type the name of an existing EmpowerID domain for which you want a Windows login tile to appear on the Login page and then click the tile for that domain.
If you have not set up an IdP Domain for your environment, you can do so by following the directions in the below drop-down.
ClickSaveto close theAdd Domaindialog.
Back in theConnections Detailspage, clickSaveto save your changes.
To test the SSO connection
From the Navigation Sidebar, expand IT Shop and click Workflows.
From the Workflows page, recycle the EmpowerID App Pools by clicking Recycle EmpowerID App Pools.
Log out of the EmpowerID Web interface and navigate your browser to the domain name you configured for Windows auth.
When prompted, enter your Windows credentials and then click OK.
If you chose to give users accessing your portal the ability to log in using their EmpowerID accounts (or any other account) and you didnotcreate anIP Address Range, they will be directed to the login page, where they could select a different login option. In this article, Windows Auth is the only login option for the portal so users will simply be prompted for their Windows credentials.
Depending on your organizational policy for browser settings, after their first login, users may or may not be prompted for credentials.