Configuring an SSO Application Card

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Single sign-on (SSO) applications defined in RapidIdentity are represented by cards or links. Each card contains the location of the application, the users allowed to access the application, and details about how the application is accessed (such as federated SSO or credential form-fill using the RapidIdentity Password Vault).

Configuring SSO applications is optional for Seamless Learning Access users. They should only be configured if those users will use the RapidIdentity GO! iOS app or GO! View to access browser-based applications that are not already configured as web clips on the iPad.

Requirements

Access to your RapidIdentity administrator portal

  1. Navigate to your RapidIdentity administrator portal.
  2. From the module selector, choose "Applications".
  3. Click Catalog in the sidebar.
  4. Click Add Application to create a new application definition.

    To view or edit an existing application, click the ellipsis next to the application and select Details.

  5. In the Details tab, configure the following fields:
    Name
    The application name users see in the GO! iOS app and GO! View browser.
    Icon
    The image users see alongside the name of the card.
    Description
    The first 53 characters display when viewing the application in the Enterprise View. The entire description is searchable in the GO! View and the RapidIdentity GO! iOS app.
    Owner
    The administrator that can edit the application definition settings. By default, the creator of the application definition is the owner. Any administrator with the proper privileges can be assigned in addition to or replace the creator.
    Status
    Determines whether the application displays to users with proper access. When set to Inactive, the application does not display to users that have access. The application never displays to users without access, regardless of status.
    Application URL
    The SSO federation entry point for the application. Users launch this URL from GO! View and the GO! iOS app. Depending on the federation type and the application's support for federated SSO, this URL might be a link to the application's federation entry point that triggers a SAML AuthnRequest or OIDC Authorize request back to RapidIdentity.
    Note:

    For Seamless Learning Access, specify a Managed App Configuration in the MDM solution for each iOS application using federated SSO with RapidIdentity. Configure the dictionary with the key-value settings required to direct the application into the federated SSO authentication flow, if the application supports that capability.

  6. In the SSO tab, configure the SSO settings based on the application's authentication type:
    Simple (default)
    Supports both federated SSO application links and non-federated application links. No configuration is required for these application definitions.
    LTI 1.0 Authentication
    Configure the LTI settings provided by the application vendor. LTI 1.1 applications can also be configured in this section.
    Password Vault
    Supports applications that use a login form with username and password fields. The Password Vault browser extension can be used in conjunction with Password Vault configuration settings.
    Note:

    The Password Vault Safari Browser Extension is not available for iPadOS at this time. Password Vault is supported by the GO! iOS application for browser-based web applications.

  7. Skip the Access Groups tab.

    Access groups define the relationship between the SSO application definition and the Rostering application definition. Rostering is not included as part of Seamless Learning Access. For more information on RapidIdentity Rostering, contact your Jamf Account Executive.

  8. Click Save.