Single sign-on

Blue Prism provides two methods of managing authentication to the platform:

  • Native Blue Prism Authentication
  • Single Sign-on for Blue Prism (recommended for enterprise deployments)

The choice of authentication scheme must be selected when the database is created – it cannot be changed afterwards.
Connections can be configured to different databases, and each database can implement a different Blue Prism sign-on method.

Native Blue Prism authentication

By default Blue Prism uses its own authentication mechanism. User accounts are individually created and maintained within Blue Prism and user login attempts are processed by verifying the supplied username/password combination configured in the Blue Prism database. The individual permissions and roles of users are maintained by assigning Blue Prism user roles.

Single sign-on for Blue Prism

Blue Prism supports Single Sign-on using Microsoft Active Directory Domain Services which allows users who have been authenticated by the operating system, and who are members of appropriate domain security groups, to log into Blue Prism without re-providing their credentials.

Single Sign-on benefits system administrators by giving them a single point of management and access control for large numbers of users.

Configuring single sign-on for Blue Prism

Blue Prism's implementation of single sign-on applies access controls to user accounts based on their Active Directory security group membership.

When configuring single sign-on authentication for Blue Prism it is necessary to specify the Active Directory domain where the security groups that will be associated with Blue Prism security roles will reside. Additionally the security group whose members will be granted System Administrator access must be selected.

Once the system administrators have been configured with access, the mapping between the other Blue Prism security roles and Active Directory security groups can take place.

Troubleshooting

If you experience trouble, see the Single Sign-on troubleshooting page.