- スタート アップ ガイド
- ベスト プラクティス
- テナント
- アクション
- フォルダー コンテキスト
- 自動化
- プロセス
- ジョブ
- トリガー
- ログ
- 監視
- キュー
- アセット
- ストレージ バケット
- Orchestrator のテスト
- アクション カタログ
- プロファイル
- システム管理者
- Identity Server
- 認証
- その他の構成
- Integrations
- クラシック ロボット
- トラブルシューティング
Orchestrator は、SAML 2.0 に基づくシングル サインオン認証に対応しています。これを有効化するには、サービス プロバイダー (Orchestrator および Identity Server) と ID プロバイダーの両方を適切に設定し、それらが相互に通信できるようにする必要があります。SAML が有効であり、正しく設定されていれば、[ログイン] ページにボタンが表示されます。外部の ID プロバイダーが多要素認証プロトコルを使用している場合、ユーザーが正常にログインするには、該当するルールにも従う必要があります。
Orchestrator および Identity Server は、複数の ID プロバイダーをサポートしています。このガイドでは、次の 4 つのプロバイダーについて説明します。
概要
詳細な手順に進む前に、SAML 認証を有効化するために必要な手順をおおまかに示します。
-
Orchestrator でユーザーを定義し、[ユーザー] ページで有効なメール アドレスを設定します。
-
Import the signing certificate provided by the Identity Provider to the Windows certificate store using Microsoft Management Console, and set Orchestrator/Identity Server to use it accordingly. See here how to do that.
-
Identity Server の [外部プロバイダー] ページで [Saml2] の設定に ID プロバイダー固有の設定を追加して、[有効] のチェック ボックスが選択されていることを確認します。
The above method is valid if your email address is set as a SAML attribute, however you can configure your own mapping strategy as well. See here how to do that.
Find the specific configuration and how to obtain the certificates for each Identity Provider on the dedicated pages: ADFS Authentication, Google Authentication, OKTA Authentication.