Configure Single Sign On for the Admin Console from the Imprivata Access Management Console

Imprivata enables Single Sign On access to your Imprivata Admin Console, and other Imprivata Admin Consoles, all from the Imprivata Access Management console(access.imprivata.com).

Enabling SSO to the Imprivata Admin Console requires that you:

  • Configure a connection to the Imprivata Cloud Platform.

  • Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management portal.

NOTE:

If your organization has multiple enterprises for which you are entitled, complete these steps for each enterprise.

Configure the Connection to the Imprivata Cloud Platform

Enabling SSO to the Imprivata Admin Console requires that you configure a connection to the Imprivata Cloud Platform. You require the following to complete the configuration:

  • Access to the Imprivata Appliance Console.

  • Access to the Imprivata Admin Console.

  • Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).

NOTE:

If you have already configured a connection to the Imprivata Cloud Platform, you can skip this step.

Complete the following steps to configure the connection.

Configure an IdP to authenticate users to the Imprivata Access Management portal

Enabling SSO to the Imprivata Admin Console requires that you configure an identity provider (IdP) to authenticate administrators to the Imprivata Access Management portal.

You can either:

  • Configure Imprivata Directory as a tenant-specific identity directory.

  • Integrate a third-party external IdP, such as Microsoft Entra ID, for SAML-based SSO.

Configure MFA for the Imprivata Access Management Portal

By default, Imprivata Identity administrators authenticate to the Imprivata Access Management portal using a single-factor (password).

  • You can strengthen security by requiring a password + Imprivata ID.

  • Before enabling multifactor authentication (MFA), be sure that administrators have enrolled Imprivata ID to prevent unintentional lock outs. Imprivata Identity administrators can use My Imprivata Identity (https://access.imprivata.com/me) to enroll additional authentication methods.

NOTE:

If you have configured SAML-based authentication through a third-party identity provider (IdP), MFA to the Imprivata Access Management portal is managed by the IdP.

To configure MFA:

  1. Log into the Imprivata Access Management portal (access.imprivata.com).

  2. Click the gear icon > Security.

  3. From Imprivata Access Management, select a security level that meets the needs of your organization.

  4. Click Save.

NOTE:

For more information about security levels, see the context-sensitive help that is available in the Imprivata Access Management portal.

Expected Authentication Workflow

The following details the expected authentication workflow:

  1. In your browser, go to the Imprivata Access Management portal (access.imprivata.com).

  2. Enter a username you associated with administrator access.

    The Imprivata Cloud Platform uses the administrator domain to locate your tenant in the cloud.

  3. The IdP you configured launches the authentication workflow for this user.

  4. After you successfully authenticate, click Launch to open the Imprivata Admin Console without further authentication. If you have any other Imprivata products configured (and this user has access), their admin consoles are also available to launch from this page.

    NOTE:

    When an administrator logs out of the Imprivata Access Management portal, the admin is also logged out of all consoles managed through the portal.