|
FileCloud Parameters
|
IdP Settings
|
|
IdP End Point URL
|
Identity Provider URL
|
|
Idp Username Parameter
|
Identifies the Username (must be unique for each user)
-
Usually uid or agencyUID
-
Default value: uid
NOTE: The username must be unique. If username sent by Idp is in email format, the email prefix will be used for username. The email prefix in this case must be
unique.
|
|
IdP Email Parameter
|
Identifies the email of the user (must be unique)
Default value: mail
|
|
IdP Given Name Parameter
|
Identifies the given name of the user
Default value: givenName
|
|
IdP Surname Parameter
|
Identifies the surname of the user
Default value: sn
|
|
IdP Log Out URL (Optional)
|
URL for logging out of IdP
|
|
Limit Logon to IdP Group
|
IdP Group Name
-
Specifying a group name means that a user can login through SAML SSO only when the Identity Provider indicates that the user belongs to the specified IdP group
-
The IdP must send this group name through the memberof parameter
-
The memberof parameter can include a comma separated value of all groups to which the user belongs
|
|
Show the IdP Logon Screen
|
Identifies which Logon screen the user will see:
|
|
IdP Metadata
|
Identity Provider metadata in XML Format
|
|
SSO Error Message (Optional)
Added in FileCloud 20.1
|
Custom error message that appears when a signin is invalid. Enter in HTML format.
|
|
Allow Account Signups
Added in FileCloud 20.1
|
When TRUE, during the login process, if the user account does not exist, a new FileCloud user account is created automatically.
|
|
Automatic Account Approval
Added in FileCloud 20.1
|
This setting works with the Allow Account Signups setting to determine:
-
If the account created by the user is disabled until the administrator approves it
-
If the account is approved with a specific level of access automatically without intervention from the Administrator.
-
Possible values are:
0 - No automatic approval, Admin has to approve account
1 - Automatically approve new accounts to Full User
2 - Automatically approve new accounts to Guest User
3 - Automatically approve new accounts to External User
|
|
Enable ADFS
|
No
|
|
User login token expiration match Idp expiration
|
If enabled the user token expiration will be set based on Idp expiration settings
If not enabled user token expiration will be set based on FileCloud Session Timeout
(FileCloud admin UI - Settings - Server - Session Timeout in Days)
Default: No (Not enabled)
|
|
Enable Browser-Only SSO Session Timeout
Added in FileCloud 23.232.1
|
If enabled, SSO session timeouts apply to browser sessions but not to client sessions.
|
|
Show the Idp Login Screen
|
If enabled, automatically redirect user to Idp log-in screen.
|
|
Log Level
|
Set the Log mode for the SAML Calls.
Default Value: prod (Do not use DEV for production systems)
|
|
Allow SSO for external users
Added in FileCloud 23.253
|
Only appears if feature is included in license.
If enabled, SSO option appears on login screen when an external user logs in.
Default value: Disabled.
|