GraphKnowledge

graph-studio

Adding a Basic Provider

Follow the steps below to add a Direct or Indirect Basic SSO Provider.

  1. In the Administration application, expand User Management and click SSO Config. Graph Studio displays the Single Sign On screen, which lists any existing providers. For example:

  2. Click the Add SSO Config button and select Basic Provider. Then choose Direct Basic Provider or Indirect Basic Provider, depending on the type of authentication that is used. The Create screen for that type of provider is displayed. For example:

  3. Configure the required properties and any optional settings as needed. The lists below describe the properties for Direct and Indirect providers.

    Direct

    • Title: This property sets the name for the connection that you are creating.
    • Description: This property can be used to provide a brief description of the provider configuration.
    • Enable on matched container ID: This property sets the list of container IDs to match. This provider will be active if the request container ID matches one of the listed container IDs. Click the field and select a container ID from the drop-down list. To specify multiple IDs, click the field again and select another value. To remove a container from the list, click the X on the right of the container name.
    • Realm Name: This property can be used to define the name of the security realm. The text appears in the dialog box that is displayed when the browser prompts a user for their credentials.
    • Enable on match regex: This property can be used to define regular expression rules for matching request URLs to enable. To add a rule, type an expression in the field and click Add. This provider will be active if the request URL matches any of the supplied expressions. If this field is blank, the provider will be active by default.
    • Disable on match regex: This property can be used to define regular expression rules for matching request URLs to disable. To add a rule, type an expression in the field and click Add. This provider will be inactive if the request URL matches any of the supplied expressions. If this field is blank, the provider will be active by default.
    • User Identifier: This property specifies the SSO provider attribute, such as email or username, to use for looking up users in the directory server.
    • Reject Token Velocity Template: This property allows inspection of login info to determine whether to reject the login.
    • Email Velocity Template: .
    • Username Velocity Template: .
    • Email Template regex: If an email attribute was specified as the User Identifier, this property can be used to specify a regular expression to use for identifying variations between email addresses stored by the SSO provider and email addresses returned by the directory server.
    • Email Template Replacement: This property can be used to define a replacement email template to use if there are variations found by Email Template regex.
    • User Template regex: If a username attribute was specified as the User Identifier, this property can be used to specify a regular expression to use for identifying variations between user names stored by the SSO provider and names returned by the directory server.
    • User Template Replacement: This property can be used to define a replacement user template to use if there are variations found by User Template regex.
    • Use username directly: This property controls whether the identity provider directly authenticates a user by validating a username and password or by validating an assertion about the user’s identity as defined by a separate identity provider.
    • LDAP domain: This property identifies the LDAP domain to use for user lookup.
    • LDAP email property: This property defines the LDAP email property to use to find the associated user's dn. For example, http://openanzo.org/ontologies/2008/07/Anzo#ldapEmailInfo.

    Indirect

    • Title: This property sets the name for the connection that you are creating.
    • Description: This property can be used to provide a brief description of the provider configuration.
    • Enable on matched container ID: This property sets the list of container IDs to match. This provider will be active if the request container ID matches one of the listed container IDs. Click the field and select a container ID from the drop-down list. To specify multiple IDs, click the field again and select another value. To remove a container from the list, click the X on the right of the container name.
    • Realm Name: This property can be used to define the name of the security realm. The text appears in the dialog box that is displayed when the browser prompts a user for their credentials.
    • Enable on login page: This property controls whether to display a link for this provider on the Graph Studio login screen.
    • Callback URL: This property specifies the URL that the provider should use to redirect users back to the Graph Studio application after a successful login. Include the full URL to the Graph Studio instance, through the proxy if one exists. Specify the URL in quotes and append the value with /anzo_authenticate, i.e., "hostname:port/anzo_authenticate".
    • Callback URL port replacement: This property can be used to define the port to use if the one specified in the Callback URL field is unavailable.
    • User Identifier: This property specifies the SSO provider attribute, such as email or username, to use for looking up users in the directory server.
    • Default to IDP Logout: This property controls whether to log a user out of the IDP by default when they log out of Graph Studio.
    • Reject Token Velocity Template: This property allows inspection of login info to determine whether to reject the login.
    • Email Velocity Template: .
    • Username Velocity Template: .
    • Email Template regex: If an email attribute was specified as the User Identifier, this property can be used to specify a regular expression to use for identifying variations between email addresses stored by the SSO provider and email addresses returned by the directory server.
    • Email Template Replacement: This property can be used to define a replacement email template to use if there are variations found by Email Template regex.
    • User Template regex: If a username attribute was specified as the User Identifier, this property can be used to specify a regular expression to use for identifying variations between user names stored by the SSO provider and names returned by the directory server.
    • User Template Replacement: This property can be used to define a replacement user template to use if there are variations found by User Template regex.
    • Use username directly: This property controls whether the identity provider directly authenticates a user by validating a username and password or by validating an assertion about the user’s identity as defined by a separate identity provider.
    • LDAP domain: This property identifies the LDAP domain to use for user lookup.
    • LDAP email property: This property defines the LDAP email property to use to find the associated user's dn. For example, http://openanzo.org/ontologies/2008/07/Anzo#ldapEmailInfo.
    • Icon: This property can be used to include an SSO icon on the Graph Studio login screen. To select an image, click the Icon field and select Add File.
  4. When you have finished configuring properties, click Confirm to save the provider setup.

Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/sso-basic.htm · retrieved 2026-08-23