This guide is for IT Administrators to setup ADFS for integration with Lucidity Software Products
...
To help understand what benefits are achieved by setting up ADFS, the following summary has been prepared so you can see the difference between an ADFS authenticated system and normal authentication.
Normal Authentication
- User opens login screen and enters Username and Password. There is a password reset option.
- Lucidity authenticates against the Username and Password that has been created within Lucidity Access. If this authentication fails the user is unable to log in.
...
- User is presented with a login screen for ADFS that allows them to proceed with an ADFS login ('login' button) or switch to non-domain login if they are accessing the system from outside the company network.
- Option 1 - User clicks 'Login' button.
- Lucidity obtains the current username 'from the browser' that the user used to authenticate against the network domain.
- If that username has a corresponding entry in Lucidity Access with appropriate permissions to allow entry into the application, then entry is allowed.
- If the username that was used to log onto the network is domain does not have a corresponding entry in Lucidity Access, or the user is not currently logged on to the network, then entry is not allowed.
- In the instance where entry is not possible using ADFS, the user can still revert to non-domain credentials (see step 3Option 2).
- Option 2 - User clicks 'Login with non-domain credentials' button.
- User is presented with a login screen which requires entry of a Username and Password. User enters these details.
- Lucidity authenticates against the Username and Password that has been created within Lucidity Access. If this authentication fails the user is unable to log in.
- Note that the username and password must be those recorded in Lucidity Access, as this is a non-domain login.
- User has the option of reverting the to ADFS login if they separately log onto the network and return to the browser to re-attempt authentication.
- User is presented with a login screen which requires entry of a Username and Password. User enters these details.
...
Info | ||
---|---|---|
| ||
The user must be authenticated against the local network domain in order for ADFS to function. The user must have the same username within Active Directly and Lucidity Access so that Lucidity can determine what permissions to give the user when they log in using ADFS. Lucidity still includes a non-domain login option for times when the user wishes to access Lucidity but they are not logged onto the network. |
...
ADFS Setup
Instructions for setup of ADFS can be found in the following video and instructions. You can skip some of this if ADFS is already setup.
http://www.youtube.com/embed/fwHIKlAPV0g
Widget Connector | ||
---|---|---|
|
...