The IDI platform currently uses a separate user account database for the Desktop Client than is used for the IDI web modules. Users who need access to both interfaces require two accounts and to manage these logons and passwords separately.
Integrated Security is a feature that allows IDI Desktop Client users to logon using an account created in the Security web module. This eliminates the need for users to manage multiple accounts and reduces the administrator overhead needed.
How Integrated Security Works
Overview

User Accounts
Only one user account needs to be created by administrators in the Security web module. The User ID and Password set for the user there will be used to access both IDI Desktop Client and web modules.
User Account statuses (e.g. locked, expired, disabled) are enforced regardless of which interface the user is attempting to log in to.
Authorizing IDI Desktop Client Access
Administrators can control access to IDI Desktop Client by assigning the Allow Desktop Client Log On permission. Users without this permission will receive an unauthorized notification otherwise and will not be given access to the Client.

Assigning IDI Desktop Client Permissions to an Account
Please Note
CG Client permissions must still be assigned to users in Admin Console even when Integrated Security is enabled.
User permissions for functionality in IDI Desktop Client are assigned in the Security folder of the Admin Console application. When a user account with the Allow Desktop Client Log On permission is created in the web Security module a mirror account will automatically be created in Admin Console. This is done to make assigning permissions easier for administrators.
In addition to IDI Desktop Client permissions, the following items must still be assigned to user accounts in Admin console:
CostGuard group membership
Data profiles
Limit-To Profiles
Admin Console Administration
When Integrated Security is enabled the administrator functions available in Admin Console are limited to assigning permissions and profile memberships as noted above.
User Account properties (e.g. Names, Dates, Email, property checkboxes) are displayed as read-only. Changing the values of these properties can only be done in the web Security module.
Synchronizing Users
The mirroring process for eligible user accounts from web Security to Admin Console occurs once per hour. This includes mirroring an account in Admin Console for the very first time as well as updating the properties displayed for an account.
Administrators can initiate the mirroring process immediately by right-clicking in the user grid and selecting SaaS Security User Update from the context menu.

Once the process is completed the Administrator will be shown the results of the sync process.

User Administration Walk-through
This walk-through demonstrates the typical steps for creating a user and assigning them access to both IDI Desktop Client and the web modules.
Step 1: Create the User
Open the Security module and go to User -> Users and click the Create User link.
Assign Roles to the user necessary for their access in the web modules.
Ensure at least one role contains the IDI Desktop Client permission Allow Desktop Client Log On.
Save the account when finished editing and assigning Roles.
Step 2: Admin Console Administration
Open Admin Console and specify the environment you are assigning permissions for.
Open the Security -> Users folder.
If the new user account does not appear in the User list, then right click and select the SaaS Security User Update option.
If the user still does not appear in the list, you should double check that they were assigned the Allow Desktop Client Log On permission in the previous step.
Right-click the account and select Edit.
Assign any permission profiles, data profiles, Limt-To’s or group memberships needed.
Save the account.
Enabling Integrated Security for an Existing Environment
Integrated Security is enabled on an environment-by-environment basis. Enabling this feature for non-production environments makes it easier for users logging into these by removing the need to deal with passwords that get out of synch with production or are over-written by a data refresh.
Steps for Turning on Integrated Security
Contact IDI – Enabling Integrated Security for an environment that is already in use will require assistance from IDI to complete. Please contact your Account Manager or Project Manager to initiate the process.
Importing Existing Users into Security – Administrators can export users to a CSV in Admin Console and then import this same file into Security; however, IDI will typically perform this task on the customer’s behalf.
Assigning Imported Users IDI Desktop Client Access- User imported into Security who will be accessing IDI Desktop Client will need the Allow Desktop Client Log On permission assigned in the appropriate environments.
Turning Integrated Security On –Integrated Security for an environment is a system level configuration that can only be enabled by IDI. When working to turn this feature on for an existing environment IDI will work with you to coordinate the cut-over.
Existing User Accounts
When the synchronization process runs for the first time the system will attempt to match Security users with existing accounts in Admin Console based on User Name. When a match is found the Admin Console user record is updated with the account properties as they were configured in Security. The action taken when a match is not found depends on the scenario:
User exists in Security but not Admin Console – A new user record is created in Admin Console automatically so that permissions and profiles can be assigned to it.
User exists in Admin Console but not Security – User record is ignored. It still will appear it in the Admin Console user list however it will not be able to be utilized for logons.