cancel
Showing results for 
Search instead for 
Did you mean: 

IDP Authentication setup

Rob_Lewis2
Champ in-the-making
Champ in-the-making

Can IDP be configured to always ask the user to enter their credentials everytime the login to OnBase?

1 ACCEPTED ANSWER

Jimmy_Byrne
Employee
Employee

Hello @Rob Lewis,

 

If a client is enabled with "Allow users to logon locally" they will always be prompted for either OnBase credentials or a provider (assuming one is configured).

 

b79dcc470cd443549c70920dbf46bc50 

23bc67128730426eb66eea2a0a3444b9

 

If that option is unchecked, and another provider is configured, the user will be automatically redirected to the provider for authentication. Single sign on (SSO) by the provider is managed entirely outside of the Hyland IdS. Microsoft Entra (formerly Azure), for example, refers to this as Seamless SSO. If you want users to be prompted for authentication by a third-party provider that would need to be addressed within the provider (Entra, Okta, Ping, etc.) setup.

View answer in original post

2 REPLIES 2

Jimmy_Byrne
Employee
Employee

Hello @Rob Lewis,

 

If a client is enabled with "Allow users to logon locally" they will always be prompted for either OnBase credentials or a provider (assuming one is configured).

 

b79dcc470cd443549c70920dbf46bc50 

23bc67128730426eb66eea2a0a3444b9

 

If that option is unchecked, and another provider is configured, the user will be automatically redirected to the provider for authentication. Single sign on (SSO) by the provider is managed entirely outside of the Hyland IdS. Microsoft Entra (formerly Azure), for example, refers to this as Seamless SSO. If you want users to be prompted for authentication by a third-party provider that would need to be addressed within the provider (Entra, Okta, Ping, etc.) setup.

Also, to add to what @Jimmy Byrne mentioned, it is possible that the environment may have multiple SAML Providers (or other types as well).  When this happens, you can use the Client | Allowed Identity Providers options to select a single Provider which will allow the redirect to occur automatically.  Else, the user will be prompted.

 

60db0ea931fe4435a79ec9f0d4b80da2

 

Best wishes.