Auto-create users on first sign-in
Just-in-time (JiT) provisioning creates a user account automatically the first time someone signs in through SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials., so you don't have to add each person by hand first. How you turn it on — and whether you can do it yourself — depends on which authentication tab your platform shows.
JiT provisioning creates accounts but never removes them. Removing someone in your identity provider doesn't disable or delete their iGrafx account — it stays active, keeps its group memberships, and keeps consuming its license, with nothing to flag it. When someone leaves, disable their iGrafx account yourself, or use automatic directory synchronization, where users removed from a connected directory are disabled in iGrafx too.
JiT also moves the decision about who gets an account to your identity provider: everyone it authenticates receives one on first sign-in, with no administrator reviewing them. Assign the iGrafx application to specific users or groups there rather than to your whole directory. New accounts inherit whatever the default group carries, so its licenses are consumed per user and its roles go to everyone who signs in.
Prerequisites
- SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials. is already set up for your platform — see Setting up single sign-on.
- A group for new users exists (the default is Users) with an appropriate default role. Without one, auto-created users sign in with no permissions.
Steps
Open Administration → User Management and check which authentication tab is shown. It reflects how your SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials. is set up: the iGrafx IdentityiGrafx Identity The iGrafx identity and access management service that brokers authentication between customer identity providers and Process360 Live components. Solution shows an OAuth tab, and the classic iGrafx Login shows a SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. tab.
If you have a SAML tab
You can turn JiT provisioning on yourself:
- On the SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. tab, turn on Automatically create authenticated users. Three attribute fields appear.
- In each field, enter the SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. attribute name your identity provider sends for the user's first name, last name, and email address. Your identity provider administrator can confirm these names.
- Set the group that new users are added to (the default is Users).
- Leave the tab to save. Users who authenticate through SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials. are now created on first sign-in, and each appears in Administration → User Management.
For an on-premises installation — including how to discover the attribute names from ADFS and the service restart it needs — see ADFS auto-creation of authenticated users.
If you have an OAuth tab
JiT provisioning on the OAuth tab isn't self-serve yet. Raise a request with iGrafx Customer Support to have it enabled. You can still set the group that new users are added to on first sign-in from the OAuth tab.
Related
- Setting up single sign-on
- ADFS auto-creation of authenticated users — on-premises SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. specifics