Understanding third-party authentication
Third-party authentication uses a trusted, external identity provider to validate user credentials before granting access to one or more IT systems. The authentication process returns identifying information to authorize or deny access. You can also use SSO (single-sign on) to centralize user authentication across multiple systems.
What is an identity provider?
An identity provider is a trusted external system that manages user accounts. It authenticates users and provides identity information over a distributed network to applications that depend on it.Benefits of using an identity provider
Using an identity provider has the following benefits:
- Advanced authentication requirements, such as using smartcards or Multi-Factor Authentication (MFA), can be imposed to increase confidence that a user is who they say they are.
- User deactivation is aligned with the customers' own internal policies. For example, when an employee leaves the company or is on an extended leave of absence.
- Separates the authentication process (verifying identity) from the authorization process (granting access rights).
- Using single sign-on (SSO), one user
authentication can grant access to multiple IT systems or even
organizations.Note:Security Center SaaS only uses an external identity provider for user authentication. Authorization is handled internally.
What third-party authentication methods does Security Center SaaS support?
Security Center SaaS supports the following third-party authentication methods:- Microsoft Entra ID (using OpenID Connect)
- OpenID Connect (OIDC) compliant identity providers (such as Okta, OneLogin, Google Workspace, PingFederate, and so on)
SSO in third-party authentication
Single sign-on (SSO) is the use of a single user authentication for multiple IT systems or even organizations. Organizations can integrate their corporate identity provider with Security Center SaaS to simplify the sign-in and authentication process. This gives you greater control over authentication policies such as the identity life cycle, multi-factor authentication (MFA) requirements, password complexity rules, and so on.
SSO integration uses our shared login.genetec.com authentication service, which enables end users to use a single set of credentials to access all Genetec™ cloud-based products and customer service portals. Using the new integration, your users can sign in to the following:
- Security Center SaaS
- Genetec™ Airport Badging Solution (ABS)
- Genetec ClearID™
- Genetec Clearance™
- Genetec Cloudrunner™
- Genetec Operations Center
- Genetec Portal (genetec.com)