Enterprise Single Sign-On
Axidian Access Enterprise Single Sign-On (ESSO, Enterprise SSO) implements the Single Sign-On technology for accessing the information systems of an organization. The module stores user passwords centrally and substitutes the password automatically in a hidden form when a user logs in to an application or performs other actions that require authentication.
Fields are filled in automatically after the user identity is confirmed with an authenticator. This way, Enterprise Single Sign-On relieves users of the need to memorize, write down, store, and manually enter passwords to log in to an application.
Since SSO profiles are stored centrally, users can access applications from any computer where the component is installed.
Authentication technologies
In Enterprise SSO, you can authenticate with the following authenticators:
- Email OTP
- Futronic Provider
- Hardware OTP
- Hardware TOTP
- IronLogic Z2 USB Provider
- MFA Provider
- OMNIKEY Provider
- Passcode
- Secured TOTP
- Smart Card Provider
- SMS OTP
- Software OTP
- Storage SMS OTP
- the Axidian Key mobile application (in the mode of sending one-time passwords and push notifications with login confirmation)
Supported applications
The Enterprise Single Sign-On access technology is used with Windows and web applications and is configured without interfering with either the server or the client part of the target application. To support a new application, you need to create a special template in the XML format. The template defines the application forms that are controlled. Access control is performed as a repeated authentication request, filling in fields with account data, activating the required controls, and writing an event to the log.
For information about how to add and configure supported applications in Management Console, see ESSO module.
Prerequisites
To use Enterprise SSO:
- Install the ESSO Agent module on the client computer.
- Configure the connection to Core Server.
- To work with web applications, configure the ESSO browser extension.
- Create a template of the target application using the ESSO Template Wizard utility.
- Add and configure the application in Management Console.
Install ESSO Agent
The module must be installed on user computers. Local administrator rights are required for this.
To install ESSO Agent:
- Run the installation file
Axidian Access <version number>/Axidian ESSO Agent/<version number>/AxidianID.Enterprise SSO.Agent.msiand follow the instructions of the installation wizard. - After the module installation is complete, the system must be restarted. Click Yes to restart immediately, or No to do it manually later.
To install ESSO Agent on user computers automatically, you can use Microsoft Group Policy or any other tool that allows you to distribute and install MSI packages in bulk, such as Microsoft System Center Configuration Manager.
Configure ESSO Agent
You can configure Enterprise SSO either in Registry Editor or with group policies.
Settings applied with group policies take priority over the settings specified manually in the registry. You can view the group policy settings in the registry at HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Axidian-ID\SrvLocator2.
- In registry
- In Group Policy Editor
Open Windows Registry Editor on the user computer.
Navigate to
HKEY_LOCAL_MACHINE\SOFTWARE\Axidian-ID\SrvLocator2.Open the properties of the
ServerUrlBasestring parameter.In the Value field, specify the URL of your Core Server in the format
http(s)://full_dns_server_name/am/core/.NoteWhen using the HTTPS protocol connection, install a client certificate on each Core Server.
- Add the
AxidianID.ServerUrl.admxpolicy to the computer with ESSO Agent installed. Group policy templates are located in theAxidian Access <version number>\Misc\ADMX Templatesfolder. - Open Group Policy Editor.
- Open Computer Configuration → Administrative Templates → Axidian ID → ClientConnection.
- Enable the Server connection settings policy.
- In the Core Server URL field, specify the address of your Core Server in the format
http(s)://full_dns_server_name/am/core/.
Configure the ESSO browser extension
When working with web applications, ESSO uses an extension for the Internet Explorer, Mozilla Firefox, and Google Chrome browsers. To log in to a web application, it is enough to open the service page — the extension performs authentication automatically. You do not need to start ESSO and select the application for SSO authentication manually.
- Internet Explorer
- Mozilla Firefox
- Google Chrome
The Axidian Access SSO Helper extension for Internet Explorer is installed together with ESSO Agent. To make the extension work, enable it in the browser.
If the ESSO Agent extension does not appear in the browser after the installation, go to Internet options→Advanced→Browsing and enable the Enable third-party browser extensions option.
For server operating systems, additionally go to Server manager→Local server and disable Internet Explorer Enhanced Security Configuration (IE ESC).
To configure the extension settings in Internet Explorer in bulk, use Windows group policies.
The policies are located in Local Group Policy Editor (gpedit.msc), in the User Configuration→Administrative Templates→Windows Components→Internet Explorer section.
- Enable the Automatically activate newly installed add-ons policy so that the extension is activated automatically.
- To prevent users from disabling add-ons, enable the Do not allow users to enable or disable add-ons policy.
The Axidian ID ESSO extension is installed together with the ESSO Agent module. To make the extension work, enable it in the browser.
To install the extension:
In the browser, go to the Extensions and Themes section.
In the upper right corner, click the settings icon and select Install Add-on From File.
Go to the
C:/Program Files (x86)/Axidian-Id/Enterprise SSO/Mozilla FireFox Web Extension/Content/axidian_id_esso-vX.X.xpifolder and click Open.After the extension is downloaded, click Add.
The Axidian ID ESSO extension is installed either manually or automatically with Microsoft Windows group policies.
When installing manually from the Chrome Web Store, the extension must be downloaded and enabled for each computer user.
The extension distributed with group policies is installed for all computer users. Internet access is not required for the installation.
To install the extension:
- From the Chrome Web Store
- In Group Policy Editor
- Install ESSO Agent on a computer with internet access.
- Start Google Chrome.
The extension is downloaded automatically within 1 minute. After the extension is downloaded, internet access is not required.
To make the extension work, enable it in the browser.
If the extension was removed from the browser manually, download it from the Chrome Web Store to install it again.
Start IIS Manager.
In the Connections pane, expand the server name → sites → Default Web Site node.
Right-click Default Web Site and select Add Application.
In the window that opens, specify the following settings:
- In the Alias field, specify an arbitrary application name, such as chromeplugin.
- For the Application pool setting, select DefaultAppPool.
- In the Physical path field, select the directory for the application.
Click OK.
In the application settings, open Authentication and enable Anonymous Authentication.
Place the lcjenjmcehnkfkghcflkfialplejjkdj.crx and
update.xmlfiles from theAxidian Access <version number>\Axidian ESSO Agent\<version number>\Misc\Chrome.WebExtdistribution into the application directory.In IIS Manager, go to the Default Web Site node.
In the MIME Types settings, add a new type with the .CRX extension and the
application/chromedescription.
- Configure a secure HTTPS connection for the chromeplugin application and make sure that it can be accessed from user computers.
- Add the ADM/ADMX templates to the local or central storage of administrative templates of the domain controller.
- Open Group Policy Management and create a new group policy object with an arbitrary name.
- Right-click the created group policy object and select Edit.
- In the window that opens, go to Computer Configuration→Administrative Templates→Google→Google Chrome→Extensions.
- Enable the Configure the list of force-installed apps and extensions policy.
- In the policy properties, in the Options section, click Show.
- In the window that opens, specify the extension identifier from the CRX file name and the path to the XML file in the chromeplugin directory.
- Enable the Configure extension, app, and user script install sources policy.
- Specify the address of the server where the chromeplugin application is deployed.
Add the user computers with ESSO Agent installed to the scope of the group policy object.
The extension is downloaded and installed automatically after the group policy is applied to the user computer. It may take several minutes for it to appear in the list of the extensions installed in the browser. An extension installed with group policies is marked with the corresponding symbol.