Skip to main content

Identity providers

Connecting an identity provider lets people sign in to the CyberOptix CTEM Platform with the account they already have, rather than a separate password.

Why it is worth doing​

The usual argument is convenience. The better argument is offboarding.

Without single sign-on, removing someone's access means remembering to remove it here too. With it, disabling their account at your identity provider ends their access immediately, everywhere, as a side effect of a process you already run.

Everything else follows from the same place: your password policy, your MFA requirements, your conditional access rules. There is no second set to keep in step.

Connecting one​

Configure the connection under Administration → Identity Providers. You will exchange the usual details with your provider - the platform's endpoints and identifiers, and your provider's metadata.

Keep one working local administrator until you have tested it

Misconfigured single sign-on locks everyone out, including whoever is fixing it.

Configure the connection, test a sign-in with a real account in a separate browser session, and only then move everyone across. Keep one org_admin who can still authenticate directly until you are confident.

Roles still come from here​

Authentication and authorization are separate. Your provider says who someone is; the platform says what they can do.

A newly federated user still needs a role and, usually, a business unit. Signing in successfully and seeing nothing useful almost always means authentication worked and no role was assigned.

When sign-in stops working​

The common causes, in the order worth checking:

  1. Certificate expiry. Federation certificates expire, and the failure is abrupt. Track the expiry date somewhere you will actually see it.
  2. A changed hostname or endpoint. Provider-side identifiers and redirect targets are recorded at configuration time and do not follow a change automatically. If anything about the platform's URL has changed, these need updating by hand.
  3. Provider-side policy. A new conditional access rule can block an application without anyone connecting the two events.

Identity providers here versus in Identity Exposure​

Two different things share a name:

API​

The endpoints behind this section are in the API reference.

Next​