SSO Login Experience
    • Dark
      Light

    SSO Login Experience

    • Dark
      Light

    Article summary

    Workspace Admin supports Single Sign-On (SSO) to authenticate the Administrator. When SSO is enabled, administrators can authenticate using their existing credentials without needing separate login details.

    Note:

    1. The SSO feature is available only for Acqueon Cloud customers and not for the on-premises customers.

    2. When a user who is not configured or onboarded attempts to log in, an error message is displayed.

    Admin Login Experience

    The Login experience varies based on the following configurations:

    1. Login Experience with Only Cognito

      When only Cognito is enabled, admins authenticate directly through Cognito. The login page displays the Cognito sign-in option, requiring admins to provide their Cognito credentials. In this configuration, Cognito independently manages the authentication process without involving any external IdP.

    2. Login Experience with a Single Default IdP configured

      When a default IdP is mapped, admins are redirected to the specified IdP for authentication. The mapped IdP, such as Azure AD or Okta, handles the login process, and upon successful authentication, redirects admins back to the application.

    3. Login Experience with Multiple IdPs Configured but No Default IdP

      When multiple IdPs are configured, but none is tagged as the default, the login page displays all the configured IdPs as sign-in options, along with the Cognito login fields. Admins can choose to authenticate through any of the available IdPs or log in directly using Cognito credentials.

    Login Experience with Only Amazon Cognito

    To log in to Workspace Admin with SSO where only Amazon Cognito is enabled, follow these steps:

    1. Access the Acqueon Workspace Admin URL on a web browser.

      The Amazon Cognito sign-in page is displayed.

       

    2. Provide the credentials and click Sign-in.

    3. On successful authentication, you are logged into the Acqueon Workspace administrator page.  

    Login Experience with a Single Default IDP Configured

    To log in to Workspace with SSO that is integrated and mapped to a single default IdP, follow these steps:

    1. Access the Acqueon Workspace Admin URL on a web browser.

      The login page displays the User ID field.

    2. Enter User ID and click Next.

      The page redirects to the organization’s IdP login window which could be powered by identity providers such as Okta, Azure Active Directory, and more.

      Note:

      The sign-in process may vary depending on the IdP used. The following workflow represents the sign-in process for an Azure Active Directory login window page.

    3. Type your password and click Sign in.

    4. On the Stay signed in? prompt, click Yes.

      On successful authentication, you are logged into Acqueon Workspace admin page.

    Login Experience with Multiple IdPs Configured but No Default Idp Mapped

    1. Access the Acqueon Workspace Admin URL on a web browser.

      The login page displays the User ID field.

    2. Enter your User ID and click Next.

      The page redirects to a list of multiple IdP options (those are integrated but none is configured as a default IdP).

      Note:

      The example above shows Azure AD as the only IdP. In a scenario with multiple IdPs, each IdP is listed by its name, allowing the user to select and log in through the preferred IdP.

    3. Click the required IdP name. In the above example, it is AzureAD.

    4. Follow the respective IdP sign-in procedures to complete the login process.

    5. On successful authentication, you are logged into Acqueon Workspace administrator page.

      Note:

      An account with "User" privileges cannot access the admin application and encounters the following error message.

            User exists but does not have the required role.


    Was this article helpful?

    What's Next
    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.
    ESC

    Eddy AI, facilitating knowledge discovery through conversational intelligence