Skip to content

Commit de69469

Browse files
committed
docs edits
1 parent 26a0b65 commit de69469

File tree

2 files changed

+37
-15
lines changed

2 files changed

+37
-15
lines changed

docs/vendor/enterprise-portal-invite.mdx

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,18 +42,26 @@ To configure allowed domains for a customer's Enterprise Portal invitations:
4242

4343
1. In the text box, enter a domain to add to the allowlist. Click **Add domain**. Add more domains as needed.
4444

45-
## Enable SAML Authentication (Alpha)
45+
## Enable SAML Authentication (Alpha) {#enable-saml}
4646

4747
:::note
4848
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
4949
:::
5050

51-
You can allow customers to configure and use SAML SSO for Enterprise Portal access. When enabled, customers can configure their IdP details in the Enterprise Portal. When disabled, even if customers have configured SAML, customers won't be able to use SAML SSO for Enterprise Portal access.
51+
You can enable and disable SAML authentication for the Enterprise Portal on a per customer basis. When SAML authentication is enabled, the customer can set up SAML SSO logins for the Enterprise Portal using their identity provider (IdP). When SAML authentication is disabled, Enterprise Portal users are not able to log in using SAML, even if the customer had already configured SAML for their Enterprise Portal previously. For more information, see [About SAML Logins (Alpha)](enterprise-portal-use#about-saml) in _Log In and Use the Enterprise Portal_.
52+
53+
To enable SAML authentication:
54+
55+
1. In the Vendor Portal, go to **Customers** and select the target customer.
56+
57+
1. On the customer's page, go to **Enterprise Portal access**. In the **Authentication** section, enable the **SAML Authentication** toggle.
5258

5359
![Enterprise Portal SAML authentication](/images/enterprise-portal-saml-authentication.png)
5460

5561
[View a larger version of this image](/images/enterprise-portal-saml-authentication.png)
5662

63+
After you enable SAML authentication, the customer can configure SAML in the Enterprise Portal using their IdP. For more information, see [Configure SAML Authentication (Alpha)](/vendor/enterprise-portal-use#saml) in _Log In and Use the Enterprise Portal_.
64+
5765
## Invite Users
5866

5967
This section describes how to invite users to the Enterprise Portal from the Vendor Portal. Your customers can also invite users to the Enterprise Portal from the Enterprise Portal **Team settings** page. For more information about using the **Team settings** page, see [Manage Users](enterprise-portal-use#manage-users) in _Access and Use the Enterprise Portal_.

docs/vendor/enterprise-portal-use.mdx

Lines changed: 27 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,11 @@ For information about how to access the Enterprise Portal for a customer from th
66

77
## Log In To the Enterprise Portal
88

9-
### Log in From the Invitation Email
9+
:::note
10+
If SAML authentication has been enabled and configured for the Enterprise Portal it will be the preferred login method and attempted automatically. See [Configure SAML Authentication (Alpha)](#saml) below.
11+
:::
12+
13+
### Log In From the Invitation Email
1014

1115
Users can log in to the Enterprise Portal after they are invited to join a team. See [Invite or Delete Users](#invite-or-delete-users) below.
1216

@@ -40,21 +44,21 @@ To sign up for a self-service account and log in to the Enteprise Portal:
4044

4145
[View a larger version of this image](/images/self-serve-signup-screen.png)
4246

43-
1. Go to your email account and open the automated account creation email. Follow the link provided in the email to log in.
47+
1. Go to your email account and open the automated account creation email. Follow the link provided in the email to log in.
4448

45-
### SAML Authentication (Alpha)
49+
### About SAML Logins (Alpha) {#about-saml}
4650

4751
:::note
4852
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
4953
:::
5054

51-
If SAML authentication has been enabled and configured for the Enterprise Portal it will be the preferred login method and attempted automatically.
55+
When SAML authentication is enabled and configured for your Enterprise Portal team, you can log in with your single sign-on (SSO) credentials either through your SAML Identity Provider (IdP) or the Enterprise Portal. For more information about how to configure SAML, see [Configure SAML Authentication (Alpha)](#saml) below.
5256

53-
SAML authentication also supports just-in-time (JIT) provisioning of user accounts as follows:
57+
#### Just-In-Time User Provisioning
5458

55-
1. Identity Provider (IdP) initiated SAML login attempts always allow for JIT user provisioning
56-
57-
1. Service Provider (SP) initiated SAML login attempts allow for JIT user provisioning if the user has an active pending invite. See [Invite or Delete Users](#invite-or-delete-users) below.
59+
The first time that you attempt to log in with SAML using your SSO credentials, if you do not already have an Enterprise Portal account, then your account is automatically created using just-in-time (JIT) user provisioning. JIT is handled differently depending on if you attempt to log in through your IdP or the Enterprise Portal:
60+
* IdP-initiated SAML login attempts always allow for JIT user provisioning
61+
* Enterprise Portal-initiated SAML login attempts allow for JIT user provisioning if your email address has already been invited to the team. See [Invite or Delete Users](#invite-or-delete-users) below.
5862

5963
## View Install and Update Instructions
6064

@@ -248,38 +252,48 @@ To manage service accounts in the Enterprise Portal:
248252
* To view a service account token, find the target service account in the table and click **View** under **Token**.
249253
* The revoke a service account's token, find the target service account in the table and open the menu under **Actions**. Select **Revoke**.
250254

251-
### Configure SAML Authentication (Alpha)
255+
### Configure SAML Authentication (Alpha) {#saml}
252256

253257
:::note
254258
SAML Authentication to the Enterprise Portal is Alpha and subject to change. To access this feature, a feature flag must be enabled for your team. For more information, reach out to your Replicated account representative.
255259
:::
256260

261+
:::note
262+
SAML authentication must be enabled for the customer in the Vendor Portal before they can configure SAML for their Enterprise Portal team. For more information, see [Enable SAML Authentication (Alpha)](enterprise-portal-invite#enable-saml).
263+
:::
264+
265+
To configure SAML authentication for your account:
266+
257267
1. In the Enterprise Portal, open the user account dropdown in the top right of the page and select **Team settings**.
258268

259269
![enterprise portal team settings](/images/enterprise-portal-user-account.png)
260270

261271
[View a larger version of this image](/images/enterprise-portal-user-account.png)
262272

263-
1. Click **SAML Authentication**
273+
1. Click **SAML Authentication**.
264274

265-
1. The Service provider information section will display information you can copy and paste to use in your identity provider (IdP).
275+
1. For **Service provider information**, copy the values provided and use them to configure your identity provider (IdP).
266276

267277
![enterprise portal SAML service provider information](/images/enterprise-portal-saml-sp-info.png)
268278

269279
[View a larger version of this image](/images/enterprise-portal-saml-sp-info.png)
270280

271-
1. Next, upload the required metadata XML and public certificate from your identity provider.
281+
1. Upload the required metadata XML and public certificate from your IdP.
272282

273283
![enterprise portal SAML configuration](/images/enterprise-portal-saml-config.png)
274284

275285
[View a larger version of this image](/images/enterprise-portal-saml-config.png)
276286

277-
1. Finally, select to enable or disable SAML authentication for the Enterprise Portal. Disabling SAML authentication will leave the stored configuration in place.
287+
1. Enable the **SAML authentication is enabled** toggle.
278288

279289
![enterprise portal SAML enablement](/images/enterprise-portal-saml-enable.png)
280290

281291
[View a larger version of this image](/images/enterprise-portal-saml-enable.png)
282292

293+
:::note
294+
If you disable SAML authentication, the SAML configuration details that you added to the Enterprise Portal are saved.
295+
:::
296+
283297
## Manage User Settings
284298

285299
Each user can manage their settings in the Enterprise Portal, including enabling and disabling email notifications for various system events.

0 commit comments

Comments
 (0)