{"id":86698,"date":"2023-06-05T13:10:07","date_gmt":"2023-06-05T17:10:07","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=86698"},"modified":"2024-02-02T19:45:46","modified_gmt":"2024-02-03T00:45:46","slug":"integrate-with-spaceiq","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/integrate-with-spaceiq","title":{"rendered":"Integrate with SpaceIQ"},"content":{"rendered":"\n
Use 探花大神 SAML Single Sign On (SSO) to give your users convenient but secure access to all their web applications with a single set of credentials. Automatically provision, update and deprovision users in SpaceIQ from 探花大神 using the Identity Management (SCIM) integration. Leverage this integration to centralize user lifecycle, user identity, and group management in 探花大神 for SpaceIQ. Save time and avoid mistakes, as well as potential security risks, related to manually creating users.<\/p>\n\n\n\n
Read this article to learn how to setup the SpaceIQ integration.<\/p>\n\n\n\n
Prerequisites<\/strong><\/p>\n\n\n\n <\/a>Important Considerations<\/strong><\/p>\n\n\n\n Attribute Considerations<\/strong><\/p>\n\n\n\n If this is a Bookmark Application, enter your sign-in URL in the Bookmark URL<\/strong> field.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n The SSO IdP URL<\/strong> is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n The certificate.pem will download to your local Downloads<\/strong> folder.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Users are implicitly denied access to applications. After you connect an application to 探花大神, you need to authorize user access to that application. You can authorize user access from the Application Configuration<\/strong> panel or from the Groups Configuration<\/strong> panel. <\/p>\n\n\n\n To learn how to authorize user access from the Groups Configuration<\/strong> panel, see Authorize Users to an SSO Application<\/a>.<\/p>\n\n\n\n This varies by SP.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n The following table lists attributes that 探花大神 sends to the application. See Attribute Considerations<\/a> for more information regarding attribute mapping considerations. <\/p>\n\n\n\n Learn about 探花大神 Properties and how they work with system users in our API<\/a>. <\/p>\n\n\n\n This functionality is helpful if users have already been created in the application but have not been created in 探花大神.<\/p>\n\n\n\n Tip:<\/strong> Try using the New Users-only filter when selecting users to import. This will move all of your new users to the top of the list, making them easier to identify and select.<\/p><\/div><\/div><\/div>\n\n\n\n\n
\n
\n
\n
\n
Creating a new 探花大神 Application Integration<\/strong><\/h2>\n\n\n\n
\n
<\/p><\/div>
\n
<\/p><\/div>
\n
\n
Configuring the SSO Integration<\/strong><\/h2>\n\n\n\n
To configure 探花大神<\/strong><\/h3>\n\n\n\n
\n
Download the certificate<\/strong><\/h4>\n\n\n\n
\n
<\/p><\/div>
To configure SpaceIQ<\/strong><\/h3>\n\n\n\n
\n
\n
Authorizing User SSO Access<\/strong><\/h2>\n\n\n\n
To authorize user access from the Application Configuration panel<\/strong><\/h3>\n\n\n\n
\n
Validating SSO user authentication workflow(s)<\/strong><\/h2>\n\n\n\n
IdP-initiated<\/strong> user workflow<\/strong><\/h3>\n\n\n\n
\n
SP-initiated<\/strong> user workflow<\/strong><\/h3>\n\n\n\n
\n
<\/p><\/div>
\n
Configuring the Identity Management Integration<\/strong><\/h2>\n\n\n\n
To configure SpaceIQ<\/strong><\/h3>\n\n\n\n
\n
To configure 探花大神<\/strong><\/h3>\n\n\n\n
\n
\n
Attribute Mappings<\/strong><\/h2>\n\n\n\n
SpaceIQ User Attributes<\/h3>\n
\n\n
\n \n 探花大神 Attribute <\/th>\n \n 探花大神 UI Field Name <\/th>\n \n SCIM v2 Mapping <\/th>\n \n SpaceIQ Attribute <\/th>\n <\/tr>\n \n \n username <\/td>\n \n Username <\/td>\n \n userName <\/td>\n \n IdP Username <\/td>\n <\/tr>\n \n \n active <\/td>\n \n Status <\/td>\n \n active <\/td>\n \n active <\/td>\n <\/tr>\n \n \n jobTitle <\/td>\n \n Job Title <\/td>\n \n job Title <\/td>\n \n title <\/td>\n <\/tr>\n \n \n email <\/td>\n \n Company Email <\/td>\n \n emails: value <\/td>\n \n Email <\/td>\n <\/tr>\n \n \n firstname <\/td>\n \n First Name <\/td>\n \n name.givenName <\/td>\n \n first_name <\/td>\n <\/tr>\n \n \n lastname <\/td>\n \n Last Name <\/td>\n \n name.familyName <\/td>\n \n last_name <\/td>\n <\/tr>\n \n \n firstname\/lastname <\/td>\n \n First Name\/Last Name <\/td>\n \n name.formatted <\/td>\n \n name <\/td>\n <\/tr>\n \n \n phoneNumbers.value <\/td>\n \n Work Phone <\/td>\n \n phoneNumbers.value <\/td>\n \n phone <\/td>\n <\/tr>\n \n \n addresses.locality <\/td>\n \n Work City <\/td>\n \n addresses.locality <\/td>\n \n location <\/td>\n <\/tr>\n \n \n employeeIdentifier <\/td>\n \n Employee ID <\/td>\n \n externalId <\/td>\n \n external_id <\/td>\n <\/tr>\n \n \n costcenter <\/td>\n \n CostCenter <\/td>\n \n costcenter <\/td>\n \n cost_center <\/td>\n <\/tr>\n \n \n employeeType <\/td>\n \n employeeType <\/td>\n \n userType <\/td>\n \n employment_type <\/td>\n <\/tr>\n \n \n department <\/td>\n \n Department <\/td>\n \n Department <\/td>\n \n department_name <\/td>\n <\/tr>\n \n \n company <\/td>\n \n Company <\/td>\n \n organization <\/td>\n \n department_name <\/td>\n <\/tr>\n <\/table>\n<\/div><\/div>\n\n\n\n Importing Users<\/strong><\/h2>\n\n\n\n
\n
\n
<\/p><\/div>
\n
\n
\n