Configuring and enabling single sign-on (SSO)

Available from 9.2.1. You can now use the two-factor authentication and use SSO to log on to BigFix Inventory and maintain login consistency with other applications in the enterprise. You can configure BigFix Inventory to use two-factor authentication with single sign-on based either on the exchange of Security Assertion Markup Language (SAML 2.0) token.

About this task

The solution described in this section is based on the assumption that the connection with BigFix Inventory is established via the BigFix Inventory host name. For complex scenarios, you need to manually configure SAML provider in the server.xml file and perform additional configuration of the authentication service.

Important Information

Procedure

  1. When BigFix Inventory is configured in single sign-on mode, other authentication methods: password / directory server are disabled.
    Before enabling single-on create at least one user with administrator role to be able to create other users.
  2. Each single sing-on user has to be added manually to the BigFix Inventory
  3. Use the same DNS Name for BigFix Inventory Server when accessing and configuring single sign on

Session timeout configuration when logged in through SSO

You can set the session timeout for BigFix Inventory. Refer to the steps mentioned at Session timeout.
Note: The time that you set must be greater than the current SSO time. If you set a time lower than current SSO time, BigFix Inventory times out sooner and does not redirect you to the SSO login page. It gives an error message.