Identity providers
Connecting an identity provider lets people sign in to the CyberOptix CTEM Platform with the account they already have, rather than a separate password.
Why it is worth doing
The usual argument is convenience. The better argument is offboarding.
Without single sign-on, removing someone's access means remembering to remove it here too. With it, disabling their account at your identity provider ends their access immediately, everywhere, as a side effect of a process you already run.
Everything else follows from the same place: your password policy, your MFA requirements, your conditional access rules. There is no second set to keep in step.
Connecting one
Configure the connection under Administration → Identity Providers. You will exchange the usual details with your provider - the platform's endpoints and identifiers, and your provider's metadata.
Misconfigured single sign-on locks everyone out, including whoever is fixing it.
Configure the connection, test a sign-in with a real account in a separate browser
session, and only then move everyone across. Keep one org_admin who can still
authenticate directly until you are confident.
Roles still come from here
Authentication and authorization are separate. Your provider says who someone is; the platform says what they can do.
A newly federated user still needs a role and, usually, a business unit. Signing in successfully and seeing nothing useful almost always means authentication worked and no role was assigned.
When sign-in stops working
The common causes, in the order worth checking:
- Certificate expiry. Federation certificates expire, and the failure is abrupt. Track the expiry date somewhere you will actually see it.
- A changed hostname or endpoint. Provider-side identifiers and redirect targets are recorded at configuration time and do not follow a change automatically. If anything about the platform's URL has changed, these need updating by hand.
- Provider-side policy. A new conditional access rule can block an application without anyone connecting the two events.
Identity providers here versus in Identity Exposure
Two different things share a name:
- This page is your own single sign-on: how your people authenticate into the platform.
- Identity Exposure → Inventory → Identity Providers is an assessment of federated identity stores in your environment - something the platform looks at, not something it uses.
API
The endpoints behind this section are in the API reference.
Next
- Users - assigning roles to federated users
- Roles and permissions - what to assign