Single Sign On for the Admin Console
Imprivata enables single sign-on access to your Patient Access Admin Console, and other Imprivata Admin Consoles, all from access.imprivata.com, powered by the Imprivata Cloud Platform.
Enabling SSO to the Patient Access console requires that you:
-
Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management console.
-
Configure a connection to the Imprivata Cloud Platform.
The Imprivata Access Management setup requires metadata from your identity provider's (IdP) console.
Open the console at the same time as the Imprivata Access Management setup so you can configure both as needed.
Configure an IdP to Authenticate Users to the Imprivata Access Management Console
Enabling SSO to the Patient Access console requires that you configure a third-party IdP to authenticate administrators to the Imprivata Access Management portal.
Integrate a third-party external IdP, such as Microsoft Entra ID, for SAML-based SSO.
Create the Imprivata Directory and Initial Admin
To configure Imprivata Directory:
-
Open the Imprivata Access Management setup.
-
Agree to the Cloud Features Agreement and enter information about your organization.
-
Skip to the Imprivata Identity Provider Connect screen.
-
Enter a domain for the Imprivata Directory.
NOTE:The domain name must be unique and cannot be reused across multiple tenants.
-
Enter a username and password for the initial administrator, and note the complete Imprivata username, which includes the Imprivata Directory domain
You require the complete username to log in to the Imprivata Access Management console.
-
Skip to the You're ready to go screen, and click the link to log in to the Imprivata Access Management console.
Add Administrators to Imprivata Directory
Use the initial admin to add more administrative users.
To add admins:
-
Log in to the Imprivata Access Management portal (access.imprivata.com).
-
Click the gear icon > Users > Imprivata Identity users.
All users are listed on the Imprivata Identity users page. From this page, you can:
-
Add a single user.
-
Bulk import multiple users.
For more information about adding users, see the context-sensitive help that is available in the Imprivata Access Management portal.
You can configure Microsoft Entra ID as an IdP to authenticate users to the Imprivata Access Management portal. You require access to the following to complete the configuration:
-
The Imprivata Cloud Tenant Setup.
-
The Microsoft Entra Admin center.
Save the Imprivata Service Provider Metadata
Use the Imprivata Access Management setup to create the Imprivata SP metadata file. You require this file when configuring the Entra ID enterprise application.
To create the metadata file:
-
Open the Imprivata Access Management setup.
-
Agree to the Cloud Features Agreement.
-
On the Tell us about your organization page, add your organization's user-facing name, (optional) logo, and business email address and click Continue.
NOTE:For non-production and production environments:
-
The user-facing organization name can be different. This should be a user-friendly name.
Imprivata recommends appending "test" or "non-prod" to the name for your non-production environment so you can easily identify it.
-
The logos can be different. Imprivata recommends that you create a distinctive logo for your non-production and production environments, so that you can easily identify which environment you are using.
-
The business email address must use the same domain in the non-production and production environments, but the email address itself can be different.
-
-
On the next page, click Continue to confirm your organization's details.
-
Skip to the Identity Provider Connect screen.
-
Type a name in the Name this identity provider box. Imprivata recommends that this name be the same as the Microsoft Entra SAML Toolkit you will configure in a later step in Microsoft Entra ID.
-
Copy the Imprivata SP metadata URL, paste it into a new browser tab, and save the page as an XML file.
Do not close the setup. You finish configuring the connection here after you configure the enterprise application.
Configure the Entra ID App
An Entra ID enterprise application is required to allow SAML-based SSO to the Imprivata Access Management console.
To configure the enterprise application:
-
In the Microsoft Entra admin center:
-
Create an Enterprise application for your non-production tenant:
-
Go to Overview> Getting Started >Assign users and groups and click Add user/groups.
-
Add the groups that identify users with administrative access to the Imprivata Access Management portal.
These users will have access to the Imprivata Access Management portal so they can update your organization's details, logo, and other settings related to the Imprivata Cloud.
NOTE:This group can be the same as the Admin group you define for Patient Access administrators, or a separate group, if required.
-
Add the groups that will have Admin, Manager, and View Only access to the Patient Access Admin Console.
These users will have access to the Patient Access Admin Console.
-
-
Go to Overview> Getting Started >Set up single sign-on.
-
Select SAML as the single sign-on method.
-
Click Upload metadata file and upload the Imprivata SP metadata XML file you created earlier.
-
For Basic SAML Configuration, provide the Sign on URL
https://access.imprivata.com.-
Click Save and close the Basic SAML Configuration applet.
-
-
Copy and Save Entra App Values
Using the Microsoft Entra Admin center, copy and save the following Entra app values. You use the following values to finish the configuration in the Imprivata Access Management setup:
-
The URL endpoint of federation metadata.
-
The SAML name/value pair that identifies users with administrative access.
To locate the required values:
-
In the Entra app, go to SAML certificates, and copy the App Federation Metadata URL.
-
In the Microsoft Entra admin center, copy the claim name for groups from Entra ID:
-
Click Attributes & Claims > Edit.
-
Click Add a group claim if there isn’t one already. Click Save.
-
Select All groups for the Which groups associated with the user should be returned in the claim?
BEST PRACTICE:Use Group ID as the source attribute.
Copy the claim name for groups from Entra ID and save for use in a later step.
Example
http://schemas.microsoft.com/ws/2008/06/identity/claims/groups. -
-
-
Go to Manage > Groups > Search, and search for a group that should have administrator access to the Imprivata Access Management portal.
Copy the Object ID for that group and save for use in the next step.
Use the Entra App Values to Finish the Configuration
Using the Imprivata Access Management setup, finish configuring Entra ID as an IdP using the Entra app values saved previously.
To finish the configuration:
-
Open the Imprivata Access Management setup, and go to the Identity Provider Connect screen.
-
Enter the SAML IdP metadata URL of the Entra app, and click Continue.
-
Paste the administrator group's claim name into SAML attribute name.
-
Paste the administrator group's Object ID into SAML attribute value, and click Continue.
-
Click Go to Access URL: access.imprivata.com to test the authentication workflow to access the Imprivata Access Management portal.
NOTE:Specifying a metadata URL allows for easier maintenance. The system automatically polls the URL at regular intervals.
This ensures that your IdP configuration stays up to date with the latest metadata, such as certificate changes.
If you upload a metadata file instead, the system does not update it automatically. From the Imprivata Access Management portal, you must edit the configuration to replace the file manually or switch to a URL.
The following are generic steps to configure any external third-party IdP to authenticate users to the Imprivata Access Management portal. For example, these steps apply to Ping Identity and Okta.
To configure your IdP:
-
Open the Imprivata Cloud Tenant Setup wizard.
-
If you have not already, agree to the Cloud Features Agreement and enter information about your organization.
-
Go to the Identity Provider Connect screen.
-
Copy the Imprivata SP metadata URL and provide it to your IdP. When configuring the IdP's application:
-
Specify
https://access.imprivata.comfor the single sign-on URL. -
Recommended: configure email address as the NameID format for user identity.
-
Recommended: configure Group ID (rather than group name) as the source attribute for group claims.
-
-
Enter the SAML IdP metadata URL, and click Continue.
-
Enter the SAML name/value pair that identifies users with administrative access, and click Continue.
-
Click Go to Access URL: access.imprivata.com to test the authentication workflow to access Imprivata Access Management.
Configure the Connection to the Imprivata Cloud Platform
Enabling SSO to the Patient Access Admin Console requires that you configure a connection to the Imprivata Cloud Platform.
The Imprivata Access Management setup supports several Imprivata products on the Imprivata Cloud Platform.
For Patient Access, you will skip some steps in the setup because they are for integrating other Imprivata products.
Before You Begin
-
Optional — a PNG, JPG, or GIF of your organization logo (200 x 100 pixels or smaller, max 100KB).
-
Groups for Patient Access — In your identity provider (IdP), define the groups for Patient Access Admin Console access for your non-production environment:
-
Admin group for access to the Imprivata Access Management portal.
Define at least one group that will have administrative access to the Imprivata Access Management portal.
NOTE:This group can be the same as the Admin group you define for Patient Access administrators, or a separate group, if required.
-
Admin group for Patient Access administrators.
-
For Microsoft Entra ID, move the Microsoft Entra ID Global Admin and any other admins into this group.
-
For all other IdPs, move any other admins you’d like administrating Patient Access into this group.
-
-
Managers group for Patient Access.
-
Viewers group for Patient Access.
NOTE:When configuring your production environment, you can define similar groups specific to a production environment, or you can use the same groups as your non-production environment.
For more information, see the system requirements and roles and permissions.
-
Imprivata Access Management Setup
-
Contact the Imprivata Services team. Imprivata Services will create the following items for you:
-
Your Imprivata Cloud Platform tenants. When Imprivata Services creates your Patient Access Cloud tenants, you will receive two: a production and a non-production Cloud tenant. The Welcome email you receive contains links to both tenants' setup wizards. Click the links in the email and follow the prompts to complete the secure connections.
-
The production Cloud tenant - use for your production environment.
-
The non-production (or sandbox) Cloud tenant - use as a test or sandbox environment.
IMPORTANT:You can configure your production and non-production tenants in any order you choose.
However, the following configuration tasks assume that you are setting up the non-production environment first as a test environment.
After setting up your non-production environment, ollow the same configuration tasks again to set up your production environment, using the link to the production Cloud tenant.
Any differences between the non-production and production environment are noted as needed.
-
-
Identity Provider (IdP) Metadata URL. You will use this information in the Patient Access console to configure the SAML connection to the Imprivata Cloud platform in a later step.
-
Accessing the Imprivata Access Management Portal
To access Imprivata Access Management Portal:
-
At the login screen, enter an email address with the same domain you configured in the setup wizard, and click Continue.
You will be redirected to your IdP's login screen.
-
After authenticating with your IdP, you will be redirected to the Imprivata Access Management Portal.
-
In the Imprivata Access Management section, the Patient Access panel is displayed. Click Launch to go to your Patient Access Admin Console.
Configure MFA for the Imprivata Access Management Portal
When the Imprivata tenant is provisioned, multi-factor authentication (MFA) is enforced for administrator access to the Imprivata Access Management console.
A temporary fallback to single-factor (password-only) authentication is available for up to 30 days:
-
Administrators must set a password to authenticate to the Imprivata Access Management console and for subsequent access to My Imprivata Identity.
-
Administrators have up to 30 days to enroll an additional factor MFA. After which:
-
Administrative access to the Imprivata Access Management console is removed until the user enrolls an additional authentication method.
-
Imprivata directory administrators can continue to access My Imprivata Identity (https://access.imprivata.com/me) to enroll additional authentication methods.
-
The administrator continues to have SSO access to their product-specific console.
Next Steps
Create roles and permissions in the Patient Access Admin Console. See Patient Access Roles and Permissions.