Introduction
Login Provider settings allow you to control which authentication methods are available for each user role within your enterprise.
This helps ensure authentication requirements are applied consistently across your enterprise while allowing different user roles to use different authentication methods where required.
For information on setting up an SSO provider in Convertr, see the Convertr SSO Guide.
Configure Login Providers
Admin users can manage the Login Providers available for each user role from Enterprise > Login Providers.
Any Login Provider configured for your enterprise will be available in this section and can be enabled for the required user roles.
Available Login Providers can include:
- Password
- Password + MFA
- SSO providers configured for your enterprise
For each user role, select the Login Providers that should be available.
For example, you may require Admin and Super User roles to use SSO, while allowing other user roles to use Password + MFA.
More than one Login Provider can be enabled for a user role where required.
Saving Changes
Changing the Login Providers available for a user role may affect existing users.
If you disable a Login Provider that is currently being used by existing users, Convertr will show the number of users who will be unable to log in as a result of the change.
You will be asked to confirm the number of users before the changes are applied.
When changing Login Providers, remember that the changes can also affect your own access. If you disable the Login Provider you currently use and it is the only option available to you, you will no longer be able to log in.
Note: Users will not automatically be moved to another Login Provider. If required, their Login Provider can be updated from the Edit User page.
If a Login Provider is disabled by mistake, it can be enabled again from Enterprise > Login Providers.
Creating and Editing Users
When creating or editing a user, the Login Provider field will only display the Login Providers enabled for the selected User Type.
For example, if SSO is the only Login Provider enabled for Admin users, an Admin user can only be configured to authenticate using SSO.
If no Login Providers are enabled for a user role, that user role will not be available for selection.
Users with permission to create or edit users can select a Login Provider, but only from those permitted for the selected user role.
E.g. The below screenshot shows a user with the 'Super User' role having multiple login options available to them, as configured for their role in Enterprise > Login Providers.
The below screenshot shows a user in the 'Publisher' role have only one login option available to them, as configured for their role in Enterprise > Login Providers.
Managing MFA
Previously, Multi Factor Authentication (MFA) was enabled individually for users from the Create/Edit User page.
MFA is now managed at the enterprise level through Enterprise > Login Providers. Password + MFA is available as a Login Provider and can be enabled for the required user roles.
When creating or editing a user, Password + MFA will be available for selection if it has been enabled for that user's role, in Enterprise > Login Providers.
Permissions
The Enterprise > Login Providers configuration can only be managed by Admin users.
For Managed Enterprise customers, this configuration is managed by Convertr.