Skip to content

SSO modes for Workplace

The SSO modes for Workplace module decides which identity is presented to Workplace when a Bastion user reaches it: their own, or a single account shared by everyone. The screen holds one drop-down and, depending on the choice, a second one.

Conditional visibility

This screen only appears once the Workplace association is enabled, in Workplace association. Unlike the other screens of the Workplace scope, it does not require console merging.

Choose the mode

Field Description
Enable SSO: Two values: Enabled (default value) and Fixed.
Alias Hidden until the Fixed mode is chosen; it then becomes visible and mandatory.
Value Effect
Enabled Each user is propagated to Workplace with their own identity. No other parameter is requested.
Fixed Every user is propagated to Workplace with the single alias chosen in the Alias list — useful when Workplace must only ever see one shared service account.

The Alias list gathers the vault aliases, those of the supervised accounts and those of the embedded vault; SSH keys are excluded from it. Each entry appears as alias name (domain\account).

Save

Click Validate — it is the only button in the window.

Outcome Feedback
Success The Changes have been saved. bubble appears and the window closes.
Fixed mode without an alias The form is refused: fill in the Alias list first.
Failure Error occured during operation.