Skip to main content

Confirming federated users can sign in

Contributors netapp-lhalbert

Before you enable single sign-on (SSO), you must confirm that at least one federated user can sign in to the Grid Manager and in to the Tenant Manager for any existing tenant accounts.

What you'll need
  • You must be signed in to the Grid Manager using a supported browser.

  • You must have specific access permissions.

  • You are using Active Directory as the federated identity source and AD FS as the identity provider.

Steps
  1. If there are existing tenant accounts, confirm that none of the tenants is using its own identity source.

    Important When you enable SSO, an identity source configured in the Tenant Manager is overridden by the identity source configured in the Grid Manager. Users belonging to the tenant's identity source will no longer be able to sign in unless they have an account with the Grid Manager identity source.
    1. Sign in to the Tenant Manager for each tenant account.

    2. Select Access Control > Identity Federation.

    3. Confirm that the Enable Identity Federation check box is not selected.

    4. If it is, confirm that any federated groups that might be in use for this tenant account are no longer required, unselect the check box, and click Save.

  2. Confirm that a federated user can access the Grid Manager:

    1. From Grid Manager, select Configuration > Access Control > Admin Groups.

    2. Ensure that at least one federated group has been imported from the Active Directory identity source and that it has been assigned the Root Access permission.

    3. Sign out.

    4. Confirm you can sign back in to the Grid Manager as a user in the federated group.

  3. If there are existing tenant accounts, confirm that a federated user who has Root Access permission can sign in:

    1. From the Grid Manager, select Tenants.

    2. Select the tenant account, and click Edit Account.

    3. If the Uses Own Identity Source check box is selected, uncheck the box and click Save.

      Edit Tenant Account > Uses Own Identity Source check box not selected

      The Tenant Accounts page appears.

    4. Select the tenant account, click Sign In, and sign in to the tenant account as the local root user.

    5. From the Tenant Manager, click Access Control > Groups.

    6. Ensure that at least one federated group from the Grid Manager has been assigned the Root Access permission for this tenant.

    7. Sign out.

    8. Confirm you can sign back in to the tenant as a user in the federated group.