- Service Overview
- Billing
- Getting Started
-
User Guide
- Before You Start
- Buying an Instance
- Instance Management
-
Enterprise Administrator Guide
- Logging In to the OneAccess Administrator Portal
- User Management
-
Resources
- Overview
-
Applications
- Adding an Application
- Enabling, Disabling, or Deleting an Application
- General Information
- Authentication Integration
- Synchronization Integration
- Login Configuration
- Access Control
- Object Models
- Authorization Management
- API Permission Management
- Application Permission Management
- Security Settings
- Audit Logs
- APIs
- Authentication
- Security
- Audit
- Settings
- Common User Guide
- Key Operations Recorded by CTS
-
Best Practices
- OneAccess Best Practices
- Identity Source Integration
-
Application Integration
-
Logging In to the Huawei Cloud Through User Portal
- Introduction
- Logging In to Single Huawei Cloud Account via OneAccess Without Password (SAML - Virtual User SSO)
- Logging In to Multiple Huawei Cloud Accounts via OneAccess Without Password (SAML - Virtual User SSO)
- Logging In to Single Huawei Cloud Account via OneAccess Without Password (SAML - IAM User SSO)
- Logging In to Multiple Huawei Cloud Accounts via OneAccess Without Password (SAML - IAM User SSO)
- Logging In to Huawei Cloud via OneAccess Without Password (OIDC)
- SSO Access to Applications Through SAML
- SSO Access to Applications Through OAuth 2.0
- SSO Access to Applications Through OIDC
- SSO Access to Applications Through CAS
- SSO Access to Applications Through Plug-in Autocompletion
-
Logging In to the Huawei Cloud Through User Portal
- Data Synchronization
- Authentication Provider Integration
- Authorizing IAM Users to Access a OneAccess Instance Administrator Portal
- API Usage
- Configuring MFA for User Login
- Developer Guide
-
API Reference
- Before You Start
- API Overview
-
OneAccess APIs
-
Management APIs
- Calling APIs
- Access Credentials
-
User Management
- Creating a User
- Modifying a User
- Deleting a User
- Enabling a User
- Disabling a User
- Changing a User Password
- Verifying and Modifying the Original User Password
- Querying User Details by User ID
- Querying User Details by Username
- Querying the User List
- Authorizing an Application Account
- Querying All Authorized Application Accounts of a User
- Organization Management
- Application Organization Management
- Application Account Management
- Application Role Management
- User APIs
- Application Integration APIs
-
Management APIs
- Appendix
- FAQs
- General Reference
Copied.
Managing Authentication Providers
OneAccess supports authentication with both individual and enterprise (internal and external) authentication providers, providing a good login experience for users in your enterprise. As an administrator, you can add, modify, and delete authentication providers.
You can use both local and third-party authentication providers, and you are advised to select a secure authentication method.
This section uses WeLink as an example to describe how to configure an individual social authentication provider. For details about how to configure other authentication providers, see Authentication Provider Integration.
Adding an Authentication Provider
- Ensure that you have administrator permissions for the WeLink open platform.
- Ensure that you have created an application on the WeLink open platform.
- Log in to the administrator portal.
- On the top navigation bar, choose Authentication > Authentication Providers.
- On the Authentication Providers page, choose Enterprise Social Authentication > WeLink.
- Set the WeLink application parameters.
Table 1 Parameter description Parameter
Description
Display Name
Name of the authentication provider.
AppKey
Client ID of an application that you have created on the WeLink open platform.
AppSecret
Client secret of the application.
Source Attribute
User attribute configured for the application. mobileNumber, userNameCn, userNameEn, userEmail, and corpUserId are supported.
Related User Attribute
OneAccess user attribute to which the user attribute of the WeLink application will be mapped. Choose any attribute from the mobile number, user ID, username, and email address.
No User Associated
Select an operation that will be performed if a user is not mapped to any system user during login. The options include Bind, Bind or Register, Automatically create users, and Failed.
- Click Save.
Modifying an Authentication Provider
Modify the settings of an authentication provider.
- Log in to the administrator portal.
- On the top navigation bar, choose Authentication > Authentication Providers.
- On the Authentication Providers page, choose Enterprise Social Authentication > WeLink.
- Modify the WeLink application parameters.
- Click Save.
Deleting an Authentication Provider
- If an authentication provider is deleted, all data of the authentication provider will also be deleted and cannot be recovered.
- Enterprise social authentication providers can be disabled but cannot be deleted.
- Log in to the administrator portal.
- On the top navigation bar, choose Authentication > Authentication Providers.
- On the Authentication Providers page, click the target authentication provider.
- Click Delete in the Operation column of an authentication provider.
- In the displayed dialog box, click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot