Single Sign On for the Admin Console

Imprivata enables single sign-on access to your Patient Access Admin Console, and other Imprivata Admin Consoles, all from access.imprivata.com, powered by the Imprivata Cloud Platform.

Enabling SSO to the Patient Access console requires that you:

  • Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management console.

  • Configure a connection to the Imprivata Cloud Platform.

NOTE:

The Imprivata Access Management setup requires metadata from your identity provider's (IdP) console.

Open the console at the same time as the Imprivata Access Management setup so you can configure both as needed.

Configure an IdP to Authenticate Users to the Imprivata Access Management Console

Enabling SSO to the Patient Access console requires that you configure a third-party IdP to authenticate administrators to the Imprivata Access Management portal.

Integrate a third-party external IdP, such as Microsoft Entra ID, for SAML-based SSO.

Configure the Connection to the Imprivata Cloud Platform

Enabling SSO to the Patient Access Admin Console requires that you configure a connection to the Imprivata Cloud Platform.

IMPORTANT:

The Imprivata Access Management setup supports several Imprivata products on the Imprivata Cloud Platform.

For Patient Access, you will skip some steps in the setup because they are for integrating other Imprivata products.

Before You Begin

  • Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).

  • Groups for Patient Access — In your identity provider (IdP), define the groups for Patient Access Admin Console access for your non-production environment:

    • Admin group for access to the Imprivata Access Management portal.

      Define at least one group that will have administrative access to the Imprivata Access Management portal.

      NOTE:

      This group can be the same as the Admin group you define for Patient Access administrators, or a separate group, if required.

    • Admin group for Patient Access administrators.

      • For Microsoft Entra ID, move the Microsoft Entra ID Global Admin and any other admins into this group.

      • For all other IdPs, move any other admins you’d like administrating Patient Access into this group.

    • Managers group for Patient Access.

    • Viewers group for Patient Access.

      NOTE:

      When configuring your production environment, you can define similar groups specific to a production environment, or you can use the same groups as your non-production environment.

      For more information, see the system requirements and roles and permissions.

Imprivata Access Management Setup

  • Contact the Imprivata Services team. Imprivata Services will create the following items for you:

    • Your Imprivata Cloud Platform tenants. When Imprivata Services creates your Patient Access Cloud tenants, you will receive two: a production and a non-production Cloud tenant. The Welcome email you receive contains links to both tenants' setup wizards. Click the links in the email and follow the prompts to complete the secure connections.

      • The production Cloud tenant - use for your production environment.

      • The non-production (or sandbox) Cloud tenant - use as a test or sandbox environment.

        IMPORTANT:

        You can configure your production and non-production tenants in any order you choose.

        However, the following configuration tasks assume that you are setting up the non-production environment first as a test environment.

        After setting up your non-production environment, ollow the same configuration tasks again to set up your production environment, using the link to the production Cloud tenant.

        Any differences between the non-production and production environment are noted as needed.

    • Identity Provider (IdP) Metadata URL. You will use this information in the Patient Access console to configure the SAML connection to the Imprivata Cloud platform in a later step.

Accessing the Imprivata Access Management Portal

To access Imprivata Access Management Portal:

  1. At the login screen, enter an email address with the same domain you configured in the setup wizard, and click Continue.

    You will be redirected to your IdP's login screen.

  2. After authenticating with your IdP, you will be redirected to the Imprivata Access Management Portal.

  3. In the Imprivata Access Management section, the Patient Access panel is displayed. Click Launch to go to your Patient Access Admin Console.

Configure MFA for the Imprivata Access Management Portal

When the Imprivata tenant is provisioned, multi-factor authentication (MFA) is enforced for administrator access to the Imprivata Access Management console.

A temporary fallback to single-factor (password-only) authentication is available for up to 30 days:

  • Administrators must set a password to authenticate to the Imprivata Access Management console and for subsequent access to My Imprivata Identity.

  • Administrators have up to 30 days to enroll an additional factor MFA. After which:

    • Administrative access to the Imprivata Access Management console is removed until the user enrolls an additional authentication method.

    • Imprivata directory administrators can continue to access My Imprivata Identity (https://access.imprivata.com/me) to enroll additional authentication methods.

NOTE:

The administrator continues to have SSO access to their product-specific console.

Next Steps

Create roles and permissions in the Patient Access Admin Console. See Patient Access Roles and Permissions.