GraphKnowledge

graph-studio

Connecting to an External User Management Provider

External user management providers offer multiple benefits to Graph Studio administrators, including:

  • Fewer potential attack points and easier maintenance
  • Simple and lightweight internal authentication
  • External integration for single sign-on (SSO) via Keycloak
  • Continued support for existing on-prem SSO providers
  • Automated user/group syncing from external idenfitication providers
  • Full management of security configurations via the Graph Studio user interface without the need for code or property files

This topic provides instructions for connecting to an external user management provider (i.e., Keycloak or SCIM).

Once your external user management provider has been configured, you can add directory users and groups to Graph Studio.

Connecting to Keycloak

The instructions provided below are made with the following assumptions:

  • At least one realm for the Graph Studio client has been configured in Keycloak.
  • You have all of the properties required to create a Keycloak OIDC configuration.
  1. In the Administration application, expand the node for Servers and select Advanced Configuration. Graph Studio displays the Advanced Configuration screen. 3. Locate the Altair Graph Studio Keycloak User Management Bundle (you can search for it by title if necessary) and select it. 5. In Advance Configuration Details, go to the Services tab and expand its contents.
  2. Provide the necessary properties. At a minimum, the following properties must be specified:
  • com.cambridgesemantics.anzo.usermanagement.keycloak.enabled
  • com.cambridgesemantics.anzo.usermanagement.keycloak.host
  • com.cambridgesemantics.anzo.usermanagement.keycloak.sslPort
  • com.cambridgesemantics.anzo.usermanagement.keycloak.useSSL
  • com.cambridgesemantics.anzo.usermanagement.keycloak.suffix
  • com.cambridgesemantics.anzo.usermanagement.keycloak.clientRealm
  • com.cambridgesemantics.anzo.usermanagement.keycloak.realmClientId
  • com.cambridgesemantics.anzo.usermanagement.keycloak.realmClientSecret

For upgrades from 5.4.x to 6.0, two other properties must be specified to ensure that existing LDAP users can still access Graph Studio:

  • com.cambridgesemantics.anzo.usermanagement.keycloak.groupUriFormat
  • com.cambridgesemantics.anzo.usermanagement.keycloak.useLdapEntryDnForUrl

When any of these properties is modified, controls display to indicate whether the change should be accepted or discarded:

Click the checkmark to accept your change or the X to discard it.

  1. Expand the node for User Managment and select SSO Configuration.
  2. Create a Keycloak OIDC Provider configuration.
  3. Expand the node for Servers and select Server Settings.Copy the value in Server Hostname.
  4. In Keycloak, go to the realm you specified in Keycloak Auth Realm in Step 6 and go to clients.
  5. Select the client you specified in Client ID in Step 6 and locate the validRedirectUri property.
  6. Add a Redirect URI and paste the hostname URL you copied in Step. Append this URL with the port number (i.e., 8443). Save your changes.

Connecting to a SCIM-supported User Management Provider

The instructions provided below are made with the following assumptions:

  • At least one realm for the Graph Studio client has been configured in Keycloak.
  • In this realm, under Configure > realmSettings > endpoints, samlIdentityProviderMetadata has been downloaded and saved (e.g., descriptor.xml).
  • You have all of the properties required to create a SAML OIDC configuration.
  1. In the Administration application, expand the node for Servers and select Advanced Configuration. Graph Studio displays the Advanced Configuration screen. 3. Locate the Altair Graph Studio SCIM User Management Bundle (you can search for it by title if necessary) and select it. 5. In Advance Configuration Details, go to the Services tab and expand its contents.
  2. Provide the necessary properties. At a minimum, the following properties must be specified:
  • com.cambridgesemantics.anzo.usermanagement.scim.useSSL
  • com.cambridgesemantics.anzo.usermanagement.scim.enabled
  • com.cambridgesemantics.anzo.usermanagement.scim.host
  • com.cambridgesemantics.anzo.usermanagement.scim.port
  • com.cambridgesemantics.anzo.usermanagement.scim.sslPort
  • com.cambridgesemantics.anzo.usermanagement.scim.suffix
  • com.cambridgesemantics.anzo.usermanagement.scim.clientId
  • com.cambridgesemantics.anzo.usermanagement.scim.clientSecret
  • com.cambridgesemantics.anzo.usermanagement.scim.tokenEndpointHost
  • com.cambridgesemantics.anzo.usermanagement.scim.tokenEndpointPort
  • com.cambridgesemantics.anzo.usermanagement.scim.tokenEndpointSslPort
  • com.cambridgesemantics.anzo.usermanagement.scim.tokenEndpointSuffix
  • com.cambridgesemantics.anzo.usermanagement.scim.tokenEndpointUseSSL
  • com.cambridgesemantics.anzo.usermanagement.scim.readonly
  • com.cambridgesemantics.anzo.usermanagement.scim.urlPrefix
  • org.openanzo.services enabled
  • org.openanzo.update.sys.config.live
  • Other Services

When any of these properties is modified, controls display to indicate whether the change should be accepted or discarded:

Click the checkmark icon to accept your change or the X to discard it.

  1. Expand the node for User Managment and select SSO Configuration.
  2. Create a SAML OIDC Provider configuration.
  3. In the Admin > Single Sign-On screen, select the SAML configuration to view its properties. Click the link provided in Service Provider Metadata to download and save the file.
  4. In Keycloak, select clients and then select importClient. Import the file you saved in Step 7. A clientID is auto-generated. Save your settings.
  5. From clientList, select the clientID generated in Step 8. Go to clientScopes and add anzoSaml (assigned type: default).
  6. Restart the Graph Studio server.

Source: https://docs.sw.siemens.com/documentation/external/PL20260212925461721/en-US/graph_studio/sso-connection.htm · retrieved 2026-08-23