TABLE OF CONTENTS
- Introduction
- How Portal Authentication Works
- Accessing the Portal Authentication Rule Editor
- Portal Authentication Rule Layout
- Configuration Settings
- Creating a Portal Authentication Rule
- Setting up Windows/Azure Authentication
- Further Support
Introduction
Portal authentication is a network access control method that requires users to authenticate themselves through a web-based portal before gaining access to the internet or specific network resources. ManagementStudio has an inbuilt portal authentication feature that helps prevent unauthorized access to data. This allows administrators to control who accesses the data/information and monitor user activity.
How Portal Authentication Works
The portal authentication process displays a login page where the user must enter credentials (such as a username and password, an access code). Once the user submits their information, the credentials are verified against an authentication server. If the credentials are valid, the user is granted access. If the credentials are invalid, the user is denied access or asked to re-enter their information. After successful authentication, the user is granted access.
Accessing the Portal Authentication Rule Editor
- Switch to Administration -> Portal Settings (1)
- Click on either New Wrapper (2) or on an existing Wrapper (3)
- In the window scroll down to the Authentication panel (4)
- Click New (5)
Portal Authentication Rule Layout
UI Elements | Description |
Rule Label | The label that will be shown in the drop down menu for selecting the Authentication. |
This page requires authentication | The User is required to be logged into ManagementStudio/AD/Azure to view this page. If Authentication is not enabled, then anyone with the Url of this page can view its content. |
Show Help | Provide more information on each of the configurations. |
Authentication Levels | |
Grid User with AD/Azure Login | These are users who are part of AD and/or Azure, but are required to be in the User Migrations Grid. |
ManagementStudio Login | These are ManagementStudio account holders. |
AD Or Azure Login | These are users who are part of AD and/or Azure, but not necessarily in the User Migrations Grid. |
Authentication Types | |
Native MS Auth | Uses ManagementStudio Username/Password to authenticate. |
Local AD Auth | Uses local AD Domain to authenticate. |
Azure AD Auth | Uses configured Azure Domain to authenticate. |
One-Time-Pass | An automatically generated numeric code used to authenticate. NB this can only be configured against Users in the grid and Domain users. The email address of the end-user needs to be found in the system. |
Multiple Auth Levels are NOT supported, please only check items of the same level (on the same row)
Configuration Settings
Authentication Level | Authentication Rule Selected | Authentication Options Displayed |
Grid User with AD/Azure Login |
| |
ManagementStudio Login |
| |
AD Or Azure Login |
|
Creating a Portal Authentication Rule
- Switch to Administration -> Portal Settings (1)
- Click on either New Wrapper (2) or on an existing Wrapper (3)
- In the window scroll down to the Authentication panel (4)
- Click New (5)
- The Portal authentication rule editor will appear similar to the below
- Enter a meaningful name for the authentication rule (1)
- Enable the checkbox 'This page requires authentication' (2)
- Select the required Authentication Type and Authentication levels (3)
- Further restrictions to the Authentication rules can be added based on the following:
- Blueprint Id
- Blueprint FolderId
- DeployUnit Id
- Role Group Id
Please see table below on the restrictions and the Authentication type it uses.
- If this is required, Click on 'Click here to add new item' (4)
- Click Save (5) to commit the changes
Restrictions | Authentication Type |
Role Group | ManagementStudio Login |
Blueprint/Deployment Unit (DU) | User Grid w/AD or Azure Login |
Setting up Windows/Azure Authentication
In order to enable windows authentication, you must install the windows authentication role service, and then enable Windows authentication for the ManagementStudio website. Please refer to this article on how to set this up.
Further Support
If you require further support, please visit ManagementStudio's Service Desk to search the knowledge base or create a new support ticket.