Single Sign On

From Displayr
Jump to: navigation, search

Displayr supports Single Sign On to allow users to log in without needing another password. When Single Sign On is enabled then your company's password system decides who can use Displayr, and which dashboards they can see.

Prerequisites

  1. You are a Displayr administrator. (You are in the Administrators group in Displayr.)
  2. Your company's password system ("Identity Provider") supports SAML2 Web Browser Single Sign-On (also known as the "SP Redirect Request; IdP POST Response" profile). E.g Microsoft Azure Active Directory. You will need help from an administrator of that system.
  3. Your company has a subdomain. e.g. mycompany.displayr.com. If you don't have one, please contact Displayr support. Once enabled, non-SSO logins must use app.displayr.com

Steps to enable

  1. Click on the cog wheel at the top right and then Account.
  2. Select the Settings pane.
  3. Scroll down and click on Configure Single Sign On (SAML).
  4. Tick Enable SAML.
  5. Have your password system's administrator fill in the other fields. Hover over the ?'s to get more information. If you are using Microsoft Azure Active Directory, see below.
  6. Click Save.

Here is an example of what the settings might look like once completed:

Saml Basic Settings.png

Known Supported Password Systems

Displayr should work with any complete implementation of SAML 2.0. The systems below have been found to work:

Microsoft Azure Active Directory

Support for Azure Active Directory will be coming soon. Please contact support if you have an immediate need for this.

Custom Implementation

See Single Sign On - Custom Implementation for help on building your own implementation of SAML 2.0, which will work with Displayr.

Groups

Users will be assigned to groups in Displayr based on the groups that they were given on your company's password system. Displayr groups control which dashboards each user can see. Your company's password system administrator must supply the codes for each security group that should be matched to Displayr. Any groups that are left blank here will be ignored by Single Sign On, and must be managed manually in Displayr.

Saml Group Settings.png

Different Types of Users

Displayr allows a mixture of manually-configured users (identified with e-mail addresses and passwords, as normal), and users who come in via Single Sign On. Single Sign On users will only appear in the Displayr Users list after successfully logging in. Either type of user can be manually put in any Displayr group. Further, Single Sign On users will be automatically added to or removed from groups each time they log in, according to your company's password system.