Arctera™ Insight Management Console Help
- Getting started
- Archive Overview
- Working with Dashboard
- Managing Configurations
- About Provisioning
- About Managed Tags
- About Account Management
- Managing Archive Collectors
- About Exchange Online Archiving
- About Google Chat Archiving
- About Google Workspace Archiving
- About SCIM Archiving
- About Import Collector
- About Insight Capture Services Archiving
- About Audio-Video Archiving
- About Audio-Video Archiving using NTR-X Collectors
- About Dubber Speik SMS Archiving
- About Dubber Speik Recordings Archiving
- About Text-Delimited Archiving
- About XSLT-XML Archiving
- About JSON Archiving
- About iMessage Archiving
- About LinkedIn Archiving
- About Signal Archiving
- About Verint Archiving
- About WeChat Archiving
- About WhatsApp Archiving
- Managing Roles and Permissions
- Managing Policies
- Managing Authentication
- Managing Retention Policies
- Managing Email Continuity Services
- Managing Reports and Notifications
- Classification
- Managing Data Import
- AD FS Configuration Guide
Selecting an authentication method
To manage secured user access to other Insight Archiving applications for example, Insight Personal Archive, you must configure the authentication service in Arctera Insight Management Console. You can select your preferred authentication method. This helps customers to centrally control access to archived databases across multiple cloud platforms by using corporate Single Sign-On (SSO) policies.
Before you configure SSO authentication, you must:
Refer to the Arctera Insight Management Console Compatibility List for supported SSO providers.
Configure your enterprise server to integrate with the archiving SSO authentication service.
Set up Active Directory user synchronization using CloudLink or MS Office 365 Sync in the Provisioning options.
To select an authentication method
- In the left navigation pane, select Policy Management > Authentication Management, and click Edit.
- Under Setup Authentication, in the Authentication Type field, select the required type of authentication method and perform the corresponding actions.
Authentication Type
Description
Cloud Archive Database
Upon selecting this option, specify the following options:
Password Change Required?:
Select Yes to ask users to change their password during their initial login after configuring their authentication setup.
Users need to provide their username and password when accessing the application that is configured for SSO. For example, Insight Personal Archive.
To understand password complexity rules, See Configuring an advanced password policy.
Select No if users do not need to change their password during their initial login.
Multi Factor Authentication Required?
Select Yes to set requirement for multi-factor authentication.
Upon selecting Yes, the Type Of Authentication Required? field appears. Currently, users can use either Email or TOTP authentication option.
Selecting Email requires users to verify via a link or OTP sent to their registered email.
Selecting TOTP requires users to authenticate using a time-based one-time password via an authenticator app.
Select No if multi-factor authentication is not required.
Click Save to finish the configuration.
Single Sign-On ADFS
Upon selecting this option, specify the following options:
Hybrid Login Allowed?:
Select Yes to enable hybrid login. The Multi Factor Authentication Required? option remains available.
Select No to disable hybrid login. The Multi Factor Authentication Required? option becomes unavailable.
Note:
This option is supported only if the Single Sign-On - ADFS authentication type is selected. For other Multi Factor Authentication options, such as Azure, Okta, OneLogin, and so on, this option remains disabled.
Role Claims Enabled?:
Select Yes to assign role-based SSO response.
Select No to avoid role-based SSO response.
Multi Factor Authentication Required?:
Select Yes to assign role-based SSO response. When Hybrid Login is enabled, multi factor authentication applies only when users log in with the CloudArchive credentials to access Insight Archiving applications.
Upon selecting Yes, the Type Of Authentication Required? field appears. Currently, users can use either Email or TOTP authentication option.
Selecting Email requires users to verify via a link or OTP sent to their registered email.
Selecting TOTP requires users to authenticate using a time-based one-time password via an authenticator app.
Select No to avoid role-based SSO response.
Unique OWA IdP:
Specifies if you want to set any external authentication service to verify user credentials while accessing Outlook.
Select Yes to specify a separate identity provider for Outlook access.
Upon selecting Yes, the Unique OWA CID field appears.
Select Yes to assign a distinct client ID for each session to enhance security by preventing unauthorized access and session hijacking.
Select No to avoid assigning a distinct client ID for each session.
Select No to avoid specifying a separate identity provider.
Your Trust Information:
Upon saving, the application displays the Customer ID, Unique OWA Client ID, and Entity ID, if enabled during configuration.
Select the I have read the instructions for setting the provided Entity ID and created my public key for upload. check box to confirm your configuration.
Click Save to finish the configuration.
Single Sign-On - SAML 2.0 based:
Upon selecting this option, specify the following options:
Hybrid Login Allowed?:
Select Yes to enable hybrid login. The Multi Factor Authentication Required? option remains available.
Select No to disable hybrid login. The Multi Factor Authentication Required? option becomes unavailable.
Note:
This option is supported only if the Single Sign-On - SAML 2.0 authentication type is selected.
Role Claims Enabled?:
Select Yes to assign role-based SSO response.
Select No to avoid role-based SSO response.
Multi Factor Authentication Required?:
Select Yes to assign role-based SSO response. When Hybrid Login is enabled, multi factor authentication applies only when users log in with the CloudArchive credentials to access Insight Archiving applications.
Upon selecting Yes, the Type Of Authentication Required? field appears. Currently, users can use either Email or TOTP authentication option.
Selecting Email requires users to verify via a link or OTP sent to their registered email.
Selecting TOTP requires users to authenticate using a time-based one-time password via an authenticator app.
Select No to avoid role-based SSO response.
Unique OWA IdP:
Specifies if you want to set any external authentication service to verify user credentials while accessing Outlook.
Select Yes to specify a separate identity provider for Outlook access.
Upon selecting Yes, the Unique OWA CID field appears.
Select Yes to assign a distinct client ID for each session to enhance security by preventing unauthorized access and session hijacking.
Select No to avoid assigning a distinct client ID for each session.
Select No to avoid specifying a separate identity provider.
Your Trust Information:
Upon saving, the application displays the Customer ID, Unique OWA Client ID, and Entity ID, if enabled during configuration.
Select the I have read the instructions for setting the provided Entity ID and created my public key for upload. check box to confirm your configuration.
Click Save to finish the configuration.