Skip to content

Commit 8223e52

Browse files
Merge pull request #3675 from replicatedhq/sc-129903_saml-docs
SAML Authentication for Enterprise Portal
2 parents c84e5ec + d3ddeaa commit 8223e52

File tree

6 files changed

+84
-4
lines changed

6 files changed

+84
-4
lines changed

docs/vendor/enterprise-portal-invite.mdx

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -42,6 +42,26 @@ To configure allowed domains for a customer's Enterprise Portal invitations:
4242

4343
1. In the text box, enter a domain to add to the allowlist. Click **Add domain**. Add more domains as needed.
4444

45+
## Enable SAML Authentication (Alpha) {#enable-saml}
46+
47+
:::note
48+
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
49+
:::
50+
51+
You can enable and disable SAML authentication for the Enterprise Portal on a per customer basis. When SAML authentication is enabled, the customer can set up SAML SSO logins for the Enterprise Portal using their identity provider (IdP). When SAML authentication is disabled, Enterprise Portal users are not able to log in using SAML, even if the customer had already configured SAML for their Enterprise Portal previously. For more information, see [About SAML Logins (Alpha)](enterprise-portal-use#about-saml) in _Log In and Use the Enterprise Portal_.
52+
53+
To enable SAML authentication:
54+
55+
1. In the Vendor Portal, go to **Customers** and select the target customer.
56+
57+
1. On the customer's page, go to **Enterprise Portal access**. In the **Authentication** section, enable the **SAML Authentication** toggle.
58+
59+
![Enterprise Portal SAML authentication](/images/enterprise-portal-saml-authentication.png)
60+
61+
[View a larger version of this image](/images/enterprise-portal-saml-authentication.png)
62+
63+
After you enable SAML authentication, the customer can configure SAML in the Enterprise Portal using their IdP. For more information, see [Configure SAML Authentication (Alpha)](/vendor/enterprise-portal-use#saml) in _Log In and Use the Enterprise Portal_.
64+
4565
## Invite Users
4666

4767
This section describes how to invite users to the Enterprise Portal from the Vendor Portal. Your customers can also invite users to the Enterprise Portal from the Enterprise Portal **Team settings** page. For more information about using the **Team settings** page, see [Manage Users](enterprise-portal-use#manage-users) in _Access and Use the Enterprise Portal_.

docs/vendor/enterprise-portal-use.mdx

Lines changed: 64 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,11 @@ For information about how to access the Enterprise Portal for a customer from th
66

77
## Log In To the Enterprise Portal
88

9-
### Log in From the Invitation Email
9+
:::note
10+
If SAML authentication has been enabled and configured for the Enterprise Portal it will be the preferred login method and attempted automatically. See [Configure SAML Authentication (Alpha)](#saml) below.
11+
:::
12+
13+
### Log In From the Invitation Email
1014

1115
Users can log in to the Enterprise Portal after they are invited to join a team. See [Invite or Delete Users](#invite-or-delete-users) below.
1216

@@ -40,7 +44,21 @@ To sign up for a self-service account and log in to the Enteprise Portal:
4044

4145
[View a larger version of this image](/images/self-serve-signup-screen.png)
4246

43-
1. Go to your email account and open the automated account creation email. Follow the link provided in the email to log in.
47+
1. Go to your email account and open the automated account creation email. Follow the link provided in the email to log in.
48+
49+
### About SAML Logins (Alpha) {#about-saml}
50+
51+
:::note
52+
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
53+
:::
54+
55+
When SAML authentication is enabled and configured for your Enterprise Portal team, you can log in with your single sign-on (SSO) credentials either through your SAML Identity Provider (IdP) or the Enterprise Portal. For more information about how to configure SAML, see [Configure SAML Authentication (Alpha)](#saml) below.
56+
57+
#### Just-In-Time User Provisioning
58+
59+
The first time that you attempt to log in with SAML using your SSO credentials, if you do not already have an Enterprise Portal account, then your account is automatically created using just-in-time (JIT) user provisioning. JIT is handled differently depending on if you attempt to log in through your IdP or the Enterprise Portal:
60+
* IdP-initiated SAML login attempts always allow for JIT user provisioning
61+
* Enterprise Portal-initiated SAML login attempts allow for JIT user provisioning if your email address has already been invited to the team. See [Invite or Delete Users](#invite-or-delete-users) below.
4462

4563
## View Install and Update Instructions
4664

@@ -197,7 +215,7 @@ To manage licenses in the Enterprise Portal:
197215

198216
## Manage Team Settings
199217

200-
This section includes information about how to manage users and service accounts in the Enterprise Portal.
218+
This section includes information about how to manage users, service accounts, and SAML authentication in the Enterprise Portal.
201219

202220
### Invite or Delete Users
203221

@@ -221,7 +239,7 @@ To manage invite and manage users in the Enterprise Portal:
221239

222240
To manage service accounts in the Enterprise Portal:
223241

224-
1. In the Enterprise Portal, openthe user account dropdown in the top right of the page and select **Team settings**.
242+
1. In the Enterprise Portal, open the user account dropdown in the top right of the page and select **Team settings**.
225243

226244
![enterprise portal team settings](/images/enterprise-portal-user-account.png)
227245

@@ -234,6 +252,48 @@ To manage service accounts in the Enterprise Portal:
234252
* To view a service account token, find the target service account in the table and click **View** under **Token**.
235253
* The revoke a service account's token, find the target service account in the table and open the menu under **Actions**. Select **Revoke**.
236254

255+
### Configure SAML Authentication (Alpha) {#saml}
256+
257+
:::note
258+
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
259+
:::
260+
261+
:::note
262+
SAML authentication must be enabled for the customer in the Vendor Portal before they can configure SAML for their Enterprise Portal team. For more information, see [Enable SAML Authentication (Alpha)](enterprise-portal-invite#enable-saml).
263+
:::
264+
265+
To configure SAML authentication for your account:
266+
267+
1. In the Enterprise Portal, open the user account dropdown in the top right of the page and select **Team settings**.
268+
269+
![enterprise portal team settings](/images/enterprise-portal-user-account.png)
270+
271+
[View a larger version of this image](/images/enterprise-portal-user-account.png)
272+
273+
1. Click **SAML Authentication**.
274+
275+
1. For **Service provider information**, copy the values provided and use them to configure your identity provider (IdP).
276+
277+
![enterprise portal SAML service provider information](/images/enterprise-portal-saml-sp-info.png)
278+
279+
[View a larger version of this image](/images/enterprise-portal-saml-sp-info.png)
280+
281+
1. Upload the required metadata XML and public certificate from your IdP.
282+
283+
![enterprise portal SAML configuration](/images/enterprise-portal-saml-config.png)
284+
285+
[View a larger version of this image](/images/enterprise-portal-saml-config.png)
286+
287+
1. After the file upload is complete, the **Enable SAML authentication** toggle is automatically enabled.
288+
289+
![enterprise portal SAML enablement](/images/enterprise-portal-saml-enable.png)
290+
291+
[View a larger version of this image](/images/enterprise-portal-saml-enable.png)
292+
293+
:::note
294+
If you disable SAML authentication, the SAML configuration details that you added to the Enterprise Portal are saved.
295+
:::
296+
237297
## Manage User Settings
238298

239299
Each user can manage their settings in the Enterprise Portal, including enabling and disabling email notifications for various system events.
47.2 KB
Loading
28.5 KB
Loading
40.1 KB
Loading
32 KB
Loading

0 commit comments

Comments
 (0)