FleetOps currently supports SSO using Microsoft only.
Note that you need to have global admin permissions in your Microsoft account to complete this setup.
Click on the Settings icon at the bottom of your navigation panel
Go to 'SSO Config' and click on 'Microsoft'
This will require you to sign into your Microsoft account and grant the permissions required to set up SSO. If your organization has set up two-factor authentication for Microsoft, you will be asked to authenticate your login.
Once all permissions have been accepted, you will be re-directed to FleetOps. The Microsoft SSO will show the status 'Ready for configuration'.
Sync User Groups
In Active Directory:
Within Active Directory, create a new group or use an existing group with the users you want to be able to access FleetOps.
Back in FleetOps:
From the Settings icon, click on SSO Configuration.
Click on the Microsoft card which should say 'Ready for configuration'.
Add the Microsoft group(s) that contain the users who should have access to FleetOps. You can search by group name or group object ID.
What is a Group Object ID?
The group Object Id is the unique identifier of a group in Azure Active Directory
Once you have selected the groups, click on 'Activate SSO'.
Your SSO setup is now complete. You will be signed out once SSO is activated and will have to sign back in with Microsoft.
FAQs on SSO setup
I am unable to set up SSO. FleetOps is showing an error.
The main error that may be preventing you from setting up SSO is if you are not a global admin in Microsoft. You will receive the below message from Microsoft in this case.
To set up SSO using Microsoft you need to have global admin permissions. This error indicates that you do not have those permissions.
Invite your global admin to FleetOps and have them configure SSO.
I see a warning that says 'users will lose access to FleetOps'. What should I do?
This warning is most likely to appear if you had users in FleetOps prior to enabling SSO. It means that some existing FleetOps users were not found in your Active Directory User groups and will therefore lose access.
Next steps:
Export the list of missing users to review if they require access to FleetOps.
If they are allowed to continue accessing FleetOps, ensure that they do not lose access by adding the missing users to the selected groups in Microsoft.
If they no longer require access to FleetOps, ignore the warning and continue to set up SSO.
We are moving to another identity provider. How can I change my SSO settings?
FleetOps currently supports SSO using Microsoft only. If you are changing identity providers, please email support@fleetops.com