Learn about setting up SSO in StorageGRID using OIDC
Setting up single sign-on (SSO) in StorageGRID allows StorageGRID (the service provider) and the SSO identity provider to communicate securely about user authentication requests.
You can set up SSO in StorageGRID using OpenID Connect (OIDC) or SAML. Follow these high-level steps to set up SSO in StorageGRID using OIDC or learn about setting up SSO using SAML.
Configure identity providerBased on the SSO identity provider you plan to use, you can select either Active Directory or Entra ID for the identity federation LDAP service type.
-
For Active Directory Federation Service (AD FS), you can use the AD FS, Entra ID, Keycloak, Okta, or PingFederate identity provider.
-
For Entra ID, you can only use the Entra ID identity provider.
Use the SSO identity provider's software to configure OIDC for each Admin Node in your grid.
-
Learn about creating an application group for each Admin Node in Active Directory
-
Learn about creating an application for each Admin Node in Entra ID
-
Learn about creating a client for each Admin Node in Keycloak
-
Learn about creating an Okta application for each Admin Node
-
Learn about creating a service provider connection for each Admin Node in PingFederate
Configure SSOSelect the Configure SSO wizard for OIDC. Then, configure SSO with your identity provider and enter sandbox mode to configure and test SSO before enabling it for StorageGRID users.
Learn about configuring SSO using OIDC
Enable SSOAfter confirming that you can use SSO to sign in to each Admin Node, enable SSO for all StorageGRID users.
Learn about enabling SSO for StorageGRID users