How to configure SSO for ServiceDesk Plus
ADSelfService plus is an identity security solution with SSO capabilities. By enabling SSO for ServiceDesk Plus through ADSelfService Plus, help desk technicians need to log in just once and access the ServiceDesk Plus console, plus all the other enterprise applications they use. Additionally, through ADSelfService Plus, access to ServiceDesk Plus can be secured with MFA.
Advantages of ADSelfService Plus' SSO
- Reduce password fatigue: Free users from having to remember different usernames and passwords for their enterprise applications; once they log in to ADSelfService Plus, they'll be able to access other applications without going through the verification process.
- Implement multi-factor authentication: Secure application logins with 19 advanced authentication factors including biometrics, YubiKey, and Google Authenticator.
- Streamline application access: Provide one-click access to all applications from a single portal.
- Increase user adoption rate of applications: Witness increased usage of applications that foster productivity due to their ready availability in the ADSelfService Plus portal.
List of authenticators available in ADSelfService Plus
On enabling SSO between ServiceDesk Plus and ADSelfService Plus, ServiceDesk Plus account logons can be secured with advanced authentication methods, as listed below:
For the complete list of authenticators, click here.
Steps to configure SSO for ServiceDesk Plus
The following steps will help you configure the single sign-on functionality between ADSelfService Plus and ServiceDesk Plus.
- Download and install ADSelfService Plus if you have not already, and complete the basic setup.
- Ensure that the ADSelfService Plus server can be accessed through an HTTPS Connection (Access URL must be configured as HTTPS).
- Log in to ADSelfService Plus as an administrator.
- Navigate to Configuration > Self-Service → Password Sync/Single Sign On → Add Application, and select ServiceDesk Plus from the applications displayed.
Note: You can also find ServiceDesk Plus from the search bar located in the left pane or the alphabet-wise navigation option in the right pane.
- Click IdP Details in the top-right corner of the screen.
- In the pop-up that appears, copy the Login URL and Logout URL, which will be used during the configuration of ServiceDesk Plus.
- Download the SSO certificate by clicking the Download X509-Certificate link.
ServiceDesk Plus (service provider) configuration steps
- Log in to ServiceDesk Plus with administrator credentials.
- Click on the Admin icon in the top-right corner.
- Navigate to Users → SAML Single Sign On.
- Under the Configuration tab, navigate to the Configure Identity Provider Details section.
- In the Login URL field, paste the Login URL value copied in Step 5 of Prerequisites.
- In the Logout URL field, enter the Logout URL value copied in Step 5 of Prerequisites.
Note: The Logout URL is optional and can be skipped if single logout (automatically log out from ADSelfService Plus when logging out from ServiceDesk Plus) is not required. The Login URL and Logout URL values must be valid domain names. For example, URLs in the following formats are supported: selfservice.com or selfservice.in.
- In the Name ID format drop-down field, select email address from the list.
- In the Algorithm drop-down field, choose the option RSA_SHA256 from the list.
- Click the Choose File button and select the file downloaded in Step 6 of Prerequisites to upload it.
- Click Save.
- After entering the identity provider details, toggle the button to enable SAML Single Sign-On.
- If you want users to log in to ServiceDesk Plus only through SAML Single Sign-On, toggle the button to enable the Collapse the login form by default option. To allow users to choose between logging in with their credentials or SAML Single Sign-On, disable this option.
- Copy the values of the Assertion Consumer URL and the Entity ID from the Service Provider Details section; these will be used later.
ADSelfService Plus (Identity Provider) configuration steps
- Switch to ADSelfService Plus' ServiceDesk Plus configuration page.
- Enter the Application Name and Description.
- In the Assign Policies field, select the policies for which SSO needs to be enabled.
Note: ADSelfService Plus allows you to create OU- and group-based policies for your AD domains. To create a policy, go to Configuration → Self-Service → Policy Configuration → Add New Policy.
- In the SAML section of the ServiceDesk Plus configuration page, select the Enable Single Sign-On check box.
- In the Assertion Consumer URL field, enter the Assertion Consumer URL copied in Step 13 of ServiceDesk Plus configuration.
- In the Entity ID field, enter the Entity ID value copied in Step 13 of ServiceDesk Plus configuration.
- Click Add Application.
Your users should now be able to sign in to ServiceDesk Plus through the ADSelfService Plus portal.
Free Active Directory users from attending lengthy help desk calls by allowing them to self-service their password resets/ account unlock tasks. Hassle-free password change for Active Directory users with ADSelfService Plus ‘Change Password’ console.
Get seamless one-click access to 100+ cloud applications. With enterprise single sign-on, users can access all their cloud applications with their Active Directory credentials. Thanks to ADSelfService Plus!
Intimate Active Directory users of their impending password/account expiry by mailing them these password/account expiry notifications.
Synchronize Windows Active Directory user password/account changes across multiple systems, automatically, including Office 365, G Suite, IBM iSeries and more.
Ensure strong user passwords that resist various hacking threats with ADSelfService Plus by enforcing Active Directory users to adhere to compliant passwords via displaying password complexity requirements.
Portal that lets Active Directory users update their latest information and a quick search facility to scout for information about peers by using search keys, like contact number, of the personality being searched.