Configure OpenID SSO for TalentLMS

These steps show you how to configure the single sign-on (SSO) functionality using OpenID to TalentLMS from ManageEngine ADSelfService Plus.

Prerequisites

  • Do not terminate the session before the configuration is complete in both the identity provider and the service provider.
  • Please enable HTTPS is the product to ensure proper functioning of single sign-on.
  1. Login to ADSelfService Plus as Super admin.
  2. Go to Configuration > Password Sync/ Single Sign On and click Add Application. Select TalentLMS from the list.
  3. Note: You can also use the search bar, in the top-left, to search for the application.
  4. Click on IdP Details and select SSO (OAuth/OpenID Connect) tab.
  5. Copy Client ID, Client Secret, Authorization Endpoint URL, Token Endpoint URL, and User Endpoint URL.
  6. Configure Oauth or OpenID Connect SSO for custom application

TalentLMS (service provider) configuration steps

  1. Login to TalentLMS account with admin credentials.
  2. Go to Home → Account & Settings → Users and click Single Sign-On (SSO).
  3. Configure Oauth or OpenID Connect SSO for custom application Configure Oauth or OpenID Connect SSO for custom application
  4. Select the SSO Integration Type as OpenID Connect from the drop-down list.
  5. Configure Oauth or OpenID Connect SSO for custom application
  6. Enter the following fields with corresponding details copied in the step 4 of Prerequisites:
    • Client id: Client ID
    • Client secret: Client Secret
    • Token endpoint: Token endpoint URL
    • User info endpoint: User Endpoint URL
    • Authorization endpoint: Authorization Endpoint URL
    Configure Oauth or OpenID Connect SSO for custom application
  7. Fill in the following fields as mentioned below:
    • Username: sub
    • First name: first_name
    • Last name: last_name
    • Email: email
    • Scope: openid email profile
  8. Click Save and check your configuration.
  9. Now, you need to copy the Authorized redirect URL from TalentLMS to configure ADSelfService Plus.
  10. Configure Oauth or OpenID Connect SSO for custom application

ADSelfService Plus (identity provider) configuration steps

  1. Switch back to ADSelfService Plus' TalentLMS configuration page.
  2. Enter the Application Name and Description as per your preference.
  3. Enter the Domain Name of your TalentLMS account. For example, if your TalentLMS username is johnwatts@thinktodaytech.com, then thinktodaytech.com is your domain name.
  4. Select policies from the Assign policies dropdown, to decide for whom this setting will be applicable.
  5. Check the box next to Enable OAuth/OpenID Connect in OAuth/OpenID Connect tab.
  6. Enter the Authorized redirect URL, from step 7 in TalentLMS configuration steps, in the Login Redirect URL field.
  7. Scopes specify the level of access the access token has. The scopes are generally provided in the authorization request so, you don't have to specify them here. If the scopes are not mentioned by your service provider, you must add them in this field.
  8. Configure Oauth or OpenID Connect SSO for custom application
  9. Click Add Application to save these settings.
  10. The Well-known Configuration URL in IdP details pop-up contains all the endpoint values, supported scopes, response modes, client authentication modes, and client details. This is enabled only after you save the application in ADSelfService Plus. You can provide this to your service provider if required.
Go to Top

Thanks!

Your request has been submitted to the ADSelfService Plus technical support team. Our technical support people will assist you at the earliest.

 

Need technical assistance?

  • Enter your email ID
  • Talk to experts
  •  
     
  •  
  • By clicking 'Talk to experts' you agree to processing of personal data according to the Privacy Policy.

Don't see what you're looking for?

  •  

    Visit our community

    Post your questions in the forum.

     
  •  

    Request additional resources

    Send us your requirements.

     
  •  

    Need implementation assistance?

    Try onboarding

     

Copyright © 2024, ZOHO Corp. All Rights Reserved.