Single Sign-On for the MAM Console

Imprivata enables single sign-on access to your MAM console and other Imprivata Admin Consoles, all from the Imprivata Access Management console (access.imprivata.com).

Enabling SSO to the MAM console requires that you:

  • Configure an identity provider (IdP) to authenticate users to the Imprivata Access Management portal.

  • Configure a connection to the Imprivata Cloud Platform.

IMPORTANT:

The MAM console only supports configuring one SAML provider.

If you use this method, it replaces any existing SAML configuration in your MAM environment.

Configure an IdP to Authenticate Users to the Imprivata Access Management Console

Enabling SSO to the MAM console requires that you configure an third-party IdP to authenticate administrators to the Imprivata Access Management console.

Integrate a third-party external IdP, such as Microsoft Entra ID, for SAML-based SSO.

NOTE:

You cannot use Imprivata as an internal IdP when configuring SSO for the MAM console.

Configure MAM SAML Settings

In the MAM console, configure SAML settings to connect to Imprivata Access Management.

  1. In the MAMconsole, go to Admin > SAML.

  2. Switch the SAML Single Sign-on setting to ON. The Configure SAML Single Sign-on dialog opens.

  3. In the Identity Provider Display Name box, type a user-friendly display name for the Imprivata Cloud platform.

  4. In the Get Metadata XML from your Identity Provider section, paste the metadata URL you received from the Imprivata Services team. This is the Identity Provider (IdP) Metadata URL referenced in the Imprivata Access Management setup section above.

  5. Click Save.

Configure MFA for the Imprivata Access Management Console

When the Imprivata tenant is provisioned, multi-factor authentication (MFA) is enforced for administrator access to the Imprivata Access Management console.

A temporary fallback to single-factor (password-only) authentication is available for up to 30 days:

  • Administrators must set a password to authenticate to the Imprivata Access Management console and for subsequent access to My Imprivata Identity.

  • Administrators have up to 30 days to enroll an additional factor MFA. After which:

    • Administrative access to the Imprivata Access Management console is removed until the user enrolls an additional authentication method.

    • Imprivata directory administrators can continue to access My Imprivata Identity (https://access.imprivata.com/me) to enroll additional authentication methods.

NOTE:

The administrator continues to have SSO access to their product-specific console.

Expected Authentication Workflow

The following details the expected authentication workflow:

  1. In your browser, go to the Imprivata Access Management console (access.imprivata.com).

  2. Enter a username you associated with administrator access.

    The Imprivata Cloud Platform uses the administrator domain to locate your tenant in the cloud.

  3. The IdP you configured launches the authentication workflow for this user.

  4. After you successfully authenticate, click Launch to open the MAM console without further authentication.

    If you have any other Imprivata products configured (and this user has access), their consoles are also available to launch from this page.