Documentation Index

Fetch the complete documentation index at: https://help.idibilling.com/llms.txt

Use this file to discover all available pages before exploring further.

IDI version 26.8 is now available.  Click here for details: IDI Updates.

Enabling Single Sign-on for your Users

Prev Next

Single Sign-on allows users to log into the IDI platform by providing their User ID and Password for an external system. In instances where users are already logged into these systems as part of their normal work day it allows them quick, easy and secure way to access the IDI platform without needing to manage yet another user identity.

This article provides an overview of Single Sign-on plus a walk through of what would be required to enable a common external provider like Office 365.

How Single Sign-on Works

Single Sign-on works by handing over users to the logon page for an external system when they want to gain access to the IDI platform. This external system, called an Authentication Provider, handles all the details around keeping track of the user’s account credentials including their User ID, and password. If the user is successful in logging into the external system then that Provider automatically redirects them back to The IDI platform. Along with sending them back the Provider lets the IDI platform know who the user is and that they are authorized to access the system. Users skip having to provider their IDI platform credentials and are sent right into the application.

A screenshot of a login screen AI-generated content may be incorrect.

Figure 1 The IDI platform Configured to Use Multiple AuthenticationProviders

Selecting an External Authentication Provider

The IDI platform supports integration with any Authentication Provider who supports the Open Authentication Standard 2.0 (OAuth).

Notable OAuth Authentication Providers include:

  • Cloud Foundry

  • Dropbox

  • Evernote

  • Google

  • Intel

  • LinkedIn

  • Microsoft (Live, Office365, Active Directory)

  • Salesforce

  • Trello

  • ZenDesk

This is just a sample list of providers, many additional software vendors and platforms support OAuth as well. To see if your existing vendors support OAuth you will need to check their documentation and resources to see what capabilities they offer.

Getting your Authentication Provider added to the IDI Platform

The IDI platform supports two providers out of the box; Salesforce and Microsoft Live. Additional providers, such as Office 365, can be added; however, since the configuration often requires customer specific information they must be added on an individual basis.

Getting a new Authentication Provider added can be initiated by contacting your Account Manager or Project Manager.

Walkthrough: Enabling Single Sign-on with Office 365

Step 1: Ensure your User Accounts are Created

Single Sign-on still requires that a user has an account in both Office 365 and in the IDI platform. Any password configured in the IDI platform will not be used however all the permissions to IDI platform modules still have to be assigned to the account in Security. In addition, the IDI platform will still check account settings such as activation date or account disabled.

The User ID’s between the two systems do not need to match when users go to link their Office 365 accounts to the IDI platform (see Step 4 below) then having the email addresses be the same makes this process simpler.

Step 2: Request to add Office 365 provider

Contact your account manager / project manager and let them know you would like to enable a new Single Sign-on provider. To setup Office 365 someone in your company who has access to the Microsoft administration portal will need to access your Active Directory instance and provide the following information to IDI:

  • Client ID

  • Client Secret

  • Authorization URI

  • Token URI

Step 3: Enable Office 365 Log on

After you are notified that IDI has added the provider go to the Security module then Policy->Domains->Domain Details page. If your company has more than one domain (e.g. employee domain and OnlineBill domain) make sure you select the domain your employees are in.

Clicking the + (add) icon next to Allowed Authorization Providers will display the interface that lets you add Single Sign-on for your users. Select Office 365 from the drop-down and leave the Show On Log in check box checked.

Figure 2 Adding a Single Sign-on Provider

Click SAVE and now the Office 365 login option should appear for your environments.

Before users can log into the IDI platform with their Office 365 account they must first link it to their IDI platform account. There are two options for doing this:

Option 1: My Account Page

After you enable the Provider for Single Sign-on, users will see a Linked Accounts link on their My Account page.

Figure3 My Account Page

Clicking the link will take them to the Configure Linked Accounts page

A red blue and black stripes AI-generated content may be incorrect.

Figure 4 Linked AccountPage

Clicking the plus sign (+) next to Office 365 will send the user to the Microsoft logon screen. If the user can successfully authenticate to Office 365 their account information is automatically linked to their IDI platform account. If the user is already logged into Office 365 they may bypass the Microsoft log in screen altogether and the link will be automatically added.

Configuration interface displaying linked accounts for 'TFOR' with available options.

Figure 5 Managing LinkedAccounts

Users can remove the link to their external account by clicking the red X next to their external account name.

Option 2: Linking via Log In Page

Users can link their IDI platform account to Office 365 without needing to first log into the IDI platform and use the My Account page.

When a user with an unlinked account clicks the Office 365 button on the IDI platform Log In page they will still be sent to Microsoft for authentication. Once they successfully log in to the Office 365 the IDI platform will look at the email address registered with Microsoft and attempt to match it to a user configured for your company in Security.

If an IDI platform account with the same email address is found then the user will see a message informing them that they are being sent a confirmation email. They will need to click the link provided in the email to complete the linking process.

A close up of a email AI-generated content may be incorrect.

Figure 6 ConfirmationDialog

If a matching The IDI platform account is not found then the user will be prompted to provide their The IDI platform user name. Once a user name is provided they will then see the Confirmation Email Sent message. The email will be sent to the email address on the user’s The IDI platform Security account, not their Office 365 account.

Regardless if their account was automatically found or not, once the user receives the confirmation email and clicks on the provided link they will see a message that the linking process is complete. They will now be able to log into The IDI platform using their Office 365 account.

User registration confirmation message with a link to log in to IDI account.

Figure 7 Registration Complete