<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Single Sign On with LDAP integration</title><link>https://community.appian.com/discussions/f/integrations/11351/single-sign-on-with-ldap-integration</link><description>Hi, 
 If we use the LDAP integration with our Active Directory that internal users are using to log in to the network, does that mean we get single sign-on automatically meaning that if the user is logged into our network and clicks on a task link or</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/65555?ContentTypeID=1</link><pubDate>Mon, 01 Apr 2019 17:52:27 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:0e6cacbf-c95c-48aa-a0b1-9ac25ec5c483</guid><dc:creator>Ankur V</dc:creator><description>&lt;p&gt;&lt;a href="/members/mangeshv"&gt;Mangesh Vidhale&lt;/a&gt; how did you integrate Ping Federate with Appian? Was this on Appian Cloud or for On-premise? We will be using Appian cloud and there is a VPN connection but direct access to LDAP from cloud is not permitted so we will are trying to use Ping with Just in time provisioning. We dont want ping to create user if the user does not exist in Appian but leverage LDAP DN, OU etc to authenticate user and move/ delete/ add users to groups based on the users LDAP settings. Is this possible using Ping Federate?&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/50402?ContentTypeID=1</link><pubDate>Mon, 27 Nov 2017 15:23:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c8e75b82-2395-470d-9983-e90dfc92a2b3</guid><dc:creator>Mangesh Vidhale</dc:creator><description>Hi Will,&lt;br /&gt;
&lt;br /&gt;
That&amp;#39;s correct. If the user is part of SAML authentication group then he will not able to login via Appian&amp;#39;s native login screen.&lt;br /&gt;
Users that do not get authenticated via SAML can login using the URL &amp;quot;&lt;a href="https://mysite.example.com/suite/portal/login.jsp&amp;quot;"&gt;mysite.example.com/.../login.jsp&amp;quot;&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Thank you.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/50362?ContentTypeID=1</link><pubDate>Mon, 27 Nov 2017 00:04:52 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:7fec10e9-f87d-4589-8b9e-f60b0a0c89a5</guid><dc:creator>Will Teoh</dc:creator><description>Hi Mangesh, so do you mean that if the user is SAML Authenticated User, he will not be able to sign in via the Appian native login screen? So in other words, for garym&amp;#39;s case, the Admin Assist. will not be able to sign in as CEO on the Admin Assist. PC if the CEO is in the SAML Authentication Users group. Am I right?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/49932?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 18:59:36 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:2e2f1a20-65fc-4189-b412-92e6a638299d</guid><dc:creator>Mangesh Vidhale</dc:creator><description>No, not through Sign Out link. I open another window and go to https://&amp;lt;site_url&amp;gt;/suite/portal/login.jsp to log in with another user (Appian user). Only non-ldap user will be able to login.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/49931?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 18:44:35 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c590b97f-4852-4da3-8020-d6546a3d0d5c</guid><dc:creator>garym</dc:creator><description>Mangesh - In your configuration, do you need to click the Log Out button before going to the https://&amp;lt;site_url&amp;gt;/suite/portal/login.jsp site or can you open another window and go to https://&amp;lt;site_url&amp;gt;/suite/portal/login.jsp to log in with another user?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/49929?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 18:41:31 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6b6d9725-cc64-4844-9fc6-fa08445a956f</guid><dc:creator>Mangesh Vidhale</dc:creator><description>&lt;p&gt;As per my understanding once you configure SSO on site, it will always try to login as SSO. I am using Ping Federate IDP in my case not sure about OKTA configurations. As a workaround you can use https://&amp;lt;site_url&amp;gt;/suite/portal/login.jsp to login with Appian user (some other user) provided the user should not be part of&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/17.2/SAML_for_Single_Sign-On.html#restrict-saml-authentication-to-specific-group"&gt;Appian SSO Group.&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/49925?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 17:42:49 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:66cccbce-293e-4bc2-95c4-6e6dbfa6f01d</guid><dc:creator>garym</dc:creator><description>Thanks Mangesh.  OK, we are implementing Okta and will integrate with our Active directory.  When that is all configured, can a user log out and get the login box if they need to login with a different account or will it always try to log in as SSO?&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Single Sign On with LDAP integration</title><link>https://community.appian.com/thread/49919?ContentTypeID=1</link><pubDate>Mon, 06 Nov 2017 14:53:05 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:3e49b928-bcee-4e32-9079-cf7f499befad</guid><dc:creator>Mangesh Vidhale</dc:creator><description>&lt;p&gt;Hi Gary,&lt;/p&gt;
&lt;p&gt;With LDAP integration, you will not get single signon automatically. Only active directory credentials will work to login to Appian through Appian login box. For single signon configuration there is separate configuration&amp;nbsp; in admin console as SAML configuration. For more details related to SAML configuration please refer link&amp;nbsp;&lt;a href="https://docs.appian.com/suite/help/17.2/SAML_for_Single_Sign-On.html"&gt;SAML Single SignOn&lt;/a&gt;. Hope this helps.&lt;/p&gt;
&lt;p&gt;Thank you.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>