Skip to main content

Login Sources (SSO)

The Login Sources SSO feature allows administrators to define the various methods by which users canauthenticate and sign into the system. ThisIts featureprimary providespurpose administratorsis withto provide flexible control over user authentication,access, allowing for standard OPSCOMdirect logins or integration with external identity providers like SAML or LDAP,LDAP enhancingto enhance convenience and securitysecurity. This article is intended for diverseOPS-COM administrators responsible for managing system access and user populations.authentication.

Setup and Configuration

This feature is a core administrative tool used to manage how different user populations access the portal.

Admin Side: Administrators must have the appropriate system role permissions enabled to access the configuration menus and manage SSO integrations.

User Side: Users will interact with the configured login sources when accessing the portal. If a Single Sign-On (SSO) source is enforced, they will automatically be redirected to their institution's secure login page before accessing the system.

Using this Feature

Administrators can use the following instructions to manage the default login source, add new external identity providers, and modify existing authentication methods.

Setup & Configuration

Login sources are managed underManaging the System Configuration menu, within the Users section.

  1. Hover over System Configuration, Users, and click Login Sources.
Default Login Source
  • OPSCOM is the default login source.source for the system. This means that, by default, users will log in directly to OPSCOMthe portal using a standard username and password created within the system itselfitself.

    on the standard login screen.
  • If you disable the OPSCOM default login source, then only your other configured login sources, such as SAML or LDAP, will be activeactive. forUsers userwill logins.

  • be
forced
to authenticate through those external providers.

Adding Login Sources

OPSCOMThe system supports multiple login sources,sources simultaneously, allowing some users to utilize SSO while others log in directly.

  1. OnHover theover System Configuration and click Users then Login Sources.

    page,
  2. click
  3. Click the Add Login Source button.

  4. FillEnter outa descriptive label into the requiredName information:field.

    • Enter the display identifier into the RedLogin fieldsSource arefield. requiredThis is what you will see on the user profile to beindicate filledif beforethe youuser canlogs clickin Savewith a special source (e.g., SSO or SAML).

    • Enter the root domain into the YellowDomain fields are technically requiredName for the login sourceOPSCOM to functionuse correctly,field. butThis they will still allow empty or invalid values tomust be savedthe initially.domain Yellowwithout fieldsany can also indicate that a change has been madereferences to the field.admin portal (for example, use CLIENTID.ops-com.com instead of CLIENTID.admin.ops-com.com/admin).

  5. The Define the Login Source - Code fieldfield. This is a crucial asidentifier it's whatthat the user profile will match against when associating users with this new login source. However, only one login source code can be activated at a time for a particular type (e.g., you can have multiple SAML configurations, but only one primary 'SAML' code active for user matching at a time if the system differentiates by 'type' of code rather than unique code string across all). The source name (code) itself is typically determined by your Identity Provider, with the exception of 'OPSCOM' for direct logins.

  6. Name can be anything that is identifiable to you.

  7. Login Source is what you will see onComplete the user profile to indicate if this user will login with a special source. Often is is calledremaining SSO or SAML
  8. Domain Name for OPSCOM to use should be set to the OPSCOM domain without any references to admin etc. For example, if the domain name you login looks like CLIENTID.admin.OPSCOM.com/admin, this should be changed to CLIENTID.OPSCOM.com only.
  9. Do not fill out the rest of the fields untilwhen you are ready to followapply the instructionspecific forsetup settinginstructions upprovided by your SSOIdentity information.Provider.

  10. Click Click the Save Changes Changes button to add the new login source.


When

Usingfilling thisout Feature

the

Onceconfiguration loginform, sourcesfields highlighted in red are added,strictly required before you can managesave. theirFields statushighlighted in yellow are technically required for the login source to function correctly, but the system will temporarily allow empty or invalid values to be saved initially. Yellow fields can also indicate that an unsaved change has been made to that specific field.

Available Actions and properties.

Managing Login Sources
Buttons

From the Loginmain Sourcesmanagement page, you can manage your configured login sources using the buttonsfollowing next to each entry:actions:

  • Edit: Click Editthis button to modify an existing login source's details. This will bring up the sameconfiguration form used for adding,form, allowing you to update its configuration.connection properties.

  • Delete: Click Deletethis button to permanently remove a login source from the list.system.

    A confirmation pop-up will usually appear before deletion.
Active/Inactive/Hidden Login Sources
  • YouStatus canDrop-down: makeSelect Logina Sourcesstatus of Active, InactiveInactive, or Hidden. for any login source. If a source is made Inactive,inactive, users who were previously connected to it will no longer be able to loginlog in and must be changedmanually migrated to a different login source.

    image.png


  • Best Practices &and Considerations

    • StrategicStrategically Planningplan for Multiplemultiple Sourcessources:: Carefully plan your login source strategy.strategy before implementation. Determine exactly which user groups will use which login method (e.g., students via SAML, staff via LDAP, and public users via OPSCOM direct login).

    • UserManage Provisioninguser provisioning:: Consider how users will be created and linked to their login sources. WillDecide theywhether profiles will be auto-created onupon their first login,successful SSO login or if they must be pre-imported?imported. This linkage usesstrictly relies on the exact string match of the Login Source - Code field.

    • DisablingTest Defaultbefore OPSCOMdisabling direct logins:: If you intend for all users to access the system via an external SSO, ensurethoroughly you disabletest the OPSCOMintegration before disabling the default OPSCOM login source. Test thoroughly before making this changesource in a live environment.

    • TestingDeactivate Newinstead Sourcesof deleting:: Always thoroughly test any new login source after configuration to ensure users can successfully authenticate and access the system.

    • Communication with Users: Clearly communicate to your users how they are expected to log in, especially if you introduce new SSO options or change existing methods. Provide clear instructions and links.
    • Inactive vs. Deleting: Use the Inactiveinactive functionstatus for temporary deactivation or if you foresee needing to reactivate a login source in the future. UseOnly use the Delete onlyaction when a login source is permanently no longer neededretired and has absolutely no associated active users.

    • Communicate changes to users: Clearly communicate to your users how they are expected to log in. If you introduce new SSO options or change existing methods, provide clear instructions and direct links on your portal homepage to prevent login confusion.