You can configure Single Sign-On with SAML in MDM Hub Console.
Before you begin Single Sign-On (SSO) configuration for the Hub Console, ensure you have the
following information:
IDP URL for the Hub Console.
Request the IDP
URL from your IT team.
IDPMetadata.xml
contains the required information.
Host Name and Port Number for the Assertion
Consumer Service (ACS) URL.
To access the console, use the following format:
http://<host>:<port>/cmx/sso/hub-console/
Single Sign-On (SSO) operations utilize the ACS URL to post the Security
Assertion Markup Language (SAML) response to the Service Provider. After
successful authentication, you are redirected to the ACS URL to exchange SAML
assertions.
Ensure the name ID in the MDM Hub Console
matches with the user name of MDM external user.
After you enable Single Sign-On in the Hub Console and run the application JAR, you can see the
SSO option available by default on the IDP login page:
You can configure Single Sign-On in the MDM Hub Console login page.
To authenticate a user on the MDM Hub Console with SSO, configure the following property in the
cmxserver.properties
file:
hubconsole.show.login.with.sso=true
The following image shows the MDM Hub Console login page with the SSO option:
For more information about configuring SAML Single Sign-On with MDM and Azure Active Directory
as the IDP, please refer to the following article: