The Security module lets administrators set up IDI platform user accounts and specify application privileges for their company’s employees.
The following functions can be performed in Security:
Creating, administering, and deleting User Accounts.
Assigning application privileges to users.
Setting logon and password policies for users.
Creating and assigning custom security roles.
Viewing Security audit and user activity logs.
For more background see:
More on Security
Security and IDI Environments
IDI platform applications typically require a user to be working within the context of one of their company’s IDI environments.
When a user logs into an application under a particular environment they can expect that the dataset they are working with is different than the one they would see if they logged into the same application, but within a different environment context.
Security works differently in this aspect because User accounts are not part of a particular environment; they are used to control access to all environments.
Administrators can open the Security module from any environment they are working in; however, the User accounts and other Security information they will see will always be the same.
In other words, all environments share the same Security users, roles, and other Security information. Any changes made in Security will impact those items across all environments.
User Account Basics
The IDI platform uses a unified sign-in system that allows users to log on to a single user account while having access to all of the available IDI resources and applications.
The same logon can be used to access different environments that a user's company may be maintaining (e.g., Production, test, training or staging).
User accounts are created by a company’s IDI platform administrator on behalf of their employees.
Accounts can be created so that the first time the user logs on they are forced to change their password and set up their account security questions.
Once users are logged on, they have access to the My Account page where they can:
Catching Up
Check out the enhancements that have been added since the last release in .
What's New
Version 21.11
More precise search for last user log-in - On the Users search page, two new fields - Last Log In: From and Last Log In: To - replace the Last Log In Prior To date filter. This lets you search for user log-in instances within a more precise date range.
Version 21.10
Restricting access to IDI environments by allowed IP addresses - New settings let you specify a pre-defined list of allowed IP addresses to restrict access to IDI web modules (Customer Care, Orders, Workflow, etc…). This helps ensure your employees or contractors are only accessing IDI environments from networks, work spaces, and computers that have proper security controls in place.
You can opt to bypass this restriction for certain power users as appropriate for your organization. For example, you may want to let trusted associates that travel frequently to access web modules from IP addresses not included in the allowed list.
Access to required setup in Security for IDI platform users requires Manage Domain permission.
For complete details on this see Restricting Access to IDI Environments by Allowed IP Addresses.
Version 18.3
Bulk Updating Users - From the User Search Results, you can now select or deselect one or more individual users on the page by checking the corresponding rows, or select and deselect all users by clicking the down arrow in the first column and choosing Select or Deselect all items on the page.
Default Activation Date to Current Day - The Activation date defaults to today’s date rather than blank (no date),
More Info Icons for Account Information and Settings Panels - Info icons have been added to several settings to provide more information.
Earlier Releases
This page lists the following Security changes for v1.09:
The IDI platform supports the ability for user to log in using account credentials from external systems. This feature is supported using the Open Authentication standard (OAuth).
Single Sign-On Authorization Codes
Customer development teams now have the ability to Single Sign-On users into the IDI platform by requesting an Authorization Code for a user from the Security API.
A new operation (CreateAuthorizationCode) has been added to the Security API which will create a temporary Authorization Code for a user account. The Authorization Code can be used in lieu of a user’s password to programmatically bypass the IDI ploatform Log In screen and send them directly into the application.
Authorization Codes provide a Single Sign-On option for customers without needing to delegate authentication to a third-party OAuth provider or to host an OAuth service themselves.
IDI Switch Environment Enhancements
Using the IDI Environment Switcher no longer requires the user to authenticate to the new environment. Prior to release 1.09 users would be presented with the Log In screen for the new environment after being logged out of their existing one.
Note
Switching Environments will still log a user out of their current application session. The Environment Switcher dialog will caution the user to save any work in-progress before switching environments.
Security Styling Updates
Security has been updated with the IDI platform 2015 web styling.
Using the Security Module
Managing Your Account (passwords, security questions, etc...)