This option allows you select either
SAMLbased login for viewers.
When you use this, you have three options:
- Public - all people with valid (google or azure based on your selection) accounts are allowed to access your deployment.)
- Filter By domain - all people with valid google or azure based accounts on the domain that you have set are allowed to access your deployment.
- Filter By viewer list - all accounts google or azure based accounts in your viewer list are allowed to access your deployment.
viewer group enterprise
Any SAML identity provider (IdP) can be configured to be used for authentication of a viewer.
To enable this, head over to the
Viewer Grouppage, then:
- 1.Select SSO as your
- 2.Now select
- 3.After this, you will be asked to provide your SAML IdP configuration.
You should see the config as follows:
SAML viewer group
- 1.Enter your IdP's
SSO redicrection URLand
X.509 signing certificate.
- 2.Click the
Savebutton to finally save your configuration.
- 3.To register GMetri as a service provider (SP) with your IdP, you will need the configuration details. You can get these details by clicking the
Download GMetri's SAML Metadatabutton.
NOTE on pasting X.509 certificate
Once you create a SAML viewer group, head to your deployment and set this viewer group as the authentication mechanism for that deployment.
- Once you open a viewer link for deployment with a SAML SSO based viewer group, you will see a pop-up with the IdP's login page.
- Post-IdP login process, you will be redirected back to
- We use your
email addresssent to us by the
IdPas the primary identifier for the viewer session.
SAML viewer IdP login
- Name Identifier format:
- In IdP
SAMLResponsewe look for the following attributes: