This is the administration screen behind ways to sign in: what you
configure here decides which buttons and forms your people see on the sign-in screen, and what
happens when they use them.
Adding a connection
Three kinds, each suited to a different arrangement:
A connection is saved with In use switched off by default. Configuring SAML or OpenID Connect
is a two-way exchange — values from your identity provider into this form, and values from this
form back into theirs — so nothing is offered to your people until you have finished both halves
and tested it.
What your identity provider needs from you
For SAML and OpenID Connect, the entity ID (or issuer), the reply URL, and — for OpenID Connect — the redirect URI, sit at the top of the panel with a copy button on each, because registering this application at the identity provider’s end is the half of the job people most often forget.Testing an LDAP connection
An LDAP connection has no console of its own to test from, so Save and test does it here: it saves the connection and reports how far it got — reached the directory, encryption negotiated, the service account accepted, a person found — rather than a bare pass or fail. Without this, the first sign of trouble is a technician failing to sign in.Who gets an account
Two independent questions for anybody arriving through a connection:- Create accounts on first sign-in — on, somebody your identity provider vouches for who has no account here gets one automatically. Off, they are refused until an administrator invites them.
- Which role they arrive with — mapped from their directory group, or a default role for anyone whose group matches nothing. Group mapping is applied on every sign-in, not only the first, so moving somebody out of a mapped group in your directory removes that role here too. Anything granted by hand on the Access screen is left alone.

