<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Login into Appian while on SSO</title><link>https://community.appian.com/discussions/f/integrations/12070/login-into-appian-while-on-sso</link><description>Hi All, 
 I have a question like, I am in client network and imagine that the Appian system is having SAML for single sign On. Do we need to again login to Appian Via Appian sign in Page, 
 Or Appian picks up the data from the User credentials from the</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53510?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 15:03:00 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:97fbf691-c4b0-4973-8332-891750f8d840</guid><dc:creator>sanjeevc0001</dc:creator><description>&lt;p&gt;True as I had indicated in the approach above but thanks for adding the extra pointers !&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff6600;"&gt;-------------&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#ff6600;"&gt;For the record this can also be done by adding the rules on the second group Customer_G1.&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53509?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 14:58:57 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:87c201db-ed53-4c4d-8fa5-286941eab7d7</guid><dc:creator>Ankur V</dc:creator><description>This can also be achieved by editing Group Membership rule for Customer_G1 and 2.Customer_G2 by adding attributes such as Name, email , city etc.The same attribute cannot be used more than once in a rule (e.g. “username like a* AND username like *b”).&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53506?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 14:43:02 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:895935c6-793d-4f83-bb28-72d489b0233f</guid><dc:creator>sanjeevc0001</dc:creator><description>So lets assume you have external link for user sign-up. Upon sign-up users will initially get the basic user profile of  Customer_G2. Now you can have an internal process to approve the users and once approved user will be assigned to elavted group Customer_G1.&lt;br /&gt;
For the record this can also be done by adding the rules on the second group Customer_G1.&lt;br /&gt;
Also if you want the SSO to create the new user if not found in the system then you may have to initate the new user creation process in LDAP/SAML behind the seen.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53505?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 14:30:57 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:327e6713-1d26-404b-99c1-fd2209251da9</guid><dc:creator>harshav</dc:creator><description>I completely agree on what is been specified in the above comments but my question is &lt;br /&gt;
&lt;br /&gt;
Imagine he is an customer who is logging in for the first time into apian system.&lt;br /&gt;
Now there are 2 groups 1.Customer_G1 and 2.Customer_G2, now based on these groups some of the data is shown on the screen.&lt;br /&gt;
Now I am thinking to add this user in to first group which is Customer_G1, how is this handled if the user is logging in with SSO and we are creating the user upon login.?&lt;br /&gt;
&lt;br /&gt;
Thank you for the above post :)&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53504?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 14:21:31 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:b7fc64cd-8e3c-488a-9242-cba5d96be36d</guid><dc:creator>sanjeevc0001</dc:creator><description>From Appian Release 17.2 onward you can display multiple sign-on links with different IDP&amp;#39;s for the users on the main sigo-on page and allow them to login by selecting approporiate link. For example:-&lt;br /&gt;
1. I am a customer  &lt;br /&gt;
2. I am an Employee&lt;br /&gt;
&lt;br /&gt;
For first link (external users)  you can have default Appian autnetication and for 2nd you can use SSO/SAML.&lt;br /&gt;
Based on their selection the authentication will be routed.&lt;br /&gt;
Hope this will help.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53503?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 14:11:02 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:fedad9be-467c-4816-9014-85ec627c6551</guid><dc:creator>harshav</dc:creator><description>it would be really great to know what are the approaches, and ways you have done handling the permissions.&lt;br /&gt;
&lt;br /&gt;
thanks :)&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53490?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 12:33:14 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:a47ed4ce-29f3-4059-b49d-70ba784d12d0</guid><dc:creator>Justin Watts</dc:creator><description>If I have internal (SSO) and external users, I typically set Appian login as the default login, and leverage web-address identifiers (&lt;a href="https://docs.appian.com/suite/help/18.1/SAML_for_Single_Sign-On.html#web-address-identifier)"&gt;docs.appian.com/.../SAML_for_Single_Sign-On.html&lt;/a&gt; to route my SSO users to the IDP.&lt;br /&gt;
&lt;br /&gt;
Once these internal users are authenticated at the IDP and forwarded into Appian, User Start Pages can be used to drive that user to an appropriate location. Again, permissions are either manually managed, or handled through automated processes talking to either RDBMS or AD.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53486?ContentTypeID=1</link><pubDate>Tue, 20 Mar 2018 09:16:22 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:c5f46753-be4b-4e1d-9e9d-65320cc4546f</guid><dc:creator>harshav</dc:creator><description>Thanks sanjeev for the details,&lt;br /&gt;
&lt;br /&gt;
But how did you manage for Internal users, did you route the users to SSO page and then, directed to Appian applications based on their security levels.&lt;br /&gt;
&lt;br /&gt;
also how did you manage the permissions or how did you set the group level access to the users , did you manually added them or any automated process is available.&lt;br /&gt;
&lt;br /&gt;
Please suggest.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53458?ContentTypeID=1</link><pubDate>Mon, 19 Mar 2018 19:03:36 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:bffefa1f-c937-4a85-af50-baa1b0cf1c35</guid><dc:creator>sanjeevc0001</dc:creator><description>You can display both SAML and Appian login on the same sign-on page if needed. SAML will be integrated and used for the single sign-on and external user can login via Appian authentication. We have used this for internal and external users. Once login the Appian access permission will be managed via Appian defined security using groups assignments.&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Login into Appian while on SSO</title><link>https://community.appian.com/thread/53448?ContentTypeID=1</link><pubDate>Mon, 19 Mar 2018 15:59:21 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:04d993d0-f031-4531-890d-27728b80f5a4</guid><dc:creator>Justin Watts</dc:creator><description>If SAML is implemented, then no, a user would not also have to login on the Appian sign-in screen. The user may have to login at their IdP, but generally teams implement Kerberos or something similar to its totally seamless. The documentation provides a decent workflow diagram of how this works: &lt;a href="https://docs.appian.com/suite/help/18.1/SAML_for_Single_Sign-On.html"&gt;docs.appian.com/.../SAML_for_Single_Sign-On.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Appian has the option to create users on login if they do not exist, but permissions would need to be updated outside of that process. My implementations I&amp;#39;ve worked with implement an sync with Active Directory to create/deactivate users, and synchronize permissions. See: &lt;a href="https://forum.appian.com/suite/sites/shared-components/page/shared-components/record/lMBCLGOdlMUpdGVqW3dQaIKmclBmvvNEj8vu_cjb7T-5YiPr4Fu8ly5Yj1s09uenE4RYzA8zKyx7eiUhe2gLnMExSh3UUdf39u81WsK_ySWyZ_LFw/view/summary"&gt;forum.appian.com/.../summary&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>