Single Sign-On (SSO) authentication is supported only for web stations.
Add an identity provider
Before you begin, create and set up an application in the identity provider. For more information, see Single Sign-On authentication.1
Launch the console
Launch the Administration and Monitoring Console.
Only the ABBYY FlexiCapture administrator can configure Single Sign-On on the default tenant. On other tenants, tenant administrators can configure it.
2
Open Single Sign-On settings
Go to Settings → Single Sign-On.
3
Add a configuration
Click Add Configuration.
4
Specify the parameters
In the dialog box that opens, specify the required parameters:
- Name – The identity provider’s name, shown on the Log in with… button.
- Reference – The URL of the external identity provider’s server.
- Upload Image File – The path to the button image (
*.svg,*.jpg, or*.png). - Upload Certificate File – The path to the public certificate.
5
Save the configuration
Click OK. The new configuration is added to the list. To change it, click Edit.
You can specify multiple identity providers.
Assign groups by SSO
You can create ABBYY FlexiCapture groups from the groups in your identity provider (IdP). Users are added automatically, and a group updates when its IdP group changes.Only the tenant administrator can assign groups. For the default tenant, only the ABBYY FlexiCapture administrator can change this setting.
1
Enable group assignment
Go to Settings → Single Sign-On and select the Assign groups by SSO option.
2
Map the IdP group
When creating a new group, enter the GUID of the corresponding IdP group in the External ID field.
SSO-only authentication mode
Use SSO-only authentication mode in high-security environments, where all access must be controlled centrally to avoid errors when granting permissions.SSO-only authentication can only be enabled for non-default tenants.
