TrueChecks clients have the ability to configure Single Sign-On (SSO) for access to the TrueChecks portal. SSO is an authentication method that allows users to access multiple sites or applications using one set of credentials, which may be ideal or appealing for an institution’s operations. Utilizing the TrueChecks SSO settings will let an IT team member perform the setup without need of assistance from AFS support.
SAML SSO Setup Overview
TrueChecks specifically utilizes a standard called Security Assertion Markup Language (SAML) in the SSO setup. SAML authentication works with three parties:
- The service provider, which is the application a user is accessing. This is TrueChecks in this case.
- The entity or identity provider, which is the authenticator that your institution would utilize.
- The client, which refers to the software being used – likely a web browser in this case.
Simply put, the web browser (client) acts as a middleman between the service provider and the entity provider, and the two providers will never connect directly. To establish this relationship, TrueChecks (the service provider) needs your institution to provide certain pieces of information about the entity provider before the setup can be complete. This can now be done directly via the TrueChecks portal.
TrueChecks Portal SSO Settings
To access the SSO configuration page, you must have the ClientAdmin role. You can select Administration on the black bar, then Client on the sub menu bar, and then Single Sign On in the side menu. Here, you will see a few text and check boxes.
The SSO Key is randomly generated by TrueChecks and is used on the entity provider settings. So, you at the financial institution will use this key in your configuration on the SSO entity provider end (ex. Microsoft Azure).
For the Identifier (Entity Id) field on the SSO provider side (ex. Microsoft Azure), the value should just be https://portal.advancedfraudsolutions.com.
-
For the Reply URL (Assertion Customer Service URL), the URL will be generated and shown at the time your account is configured in the AFS Portal. It will be in the format of https://portal.advancedfraudsolutions.com/SSO/{GUID}
- {GUID} will be the SSO Key.
The Entity ID will be provided by you from the entity provider.
The Sign On URL will also be provided by you from the entity provider.
Providing a Log Out URL is optional. By default, users will be sent to the TrueChecks portal login page when they log out; this box allows you to change where the user is sent when they log out.
You will paste the Certificate Body in the last box. It will look like a long string of random characters and should start with something like, “-----BEGIN CERTIFICATE-----" and end with something like, “-----END CERTIFICATE-----.”
The two checkboxes on the right are optional settings for forcing SSO and user auto-provisioning, explained below.
Force SSO – This option stops users from logging in via the portal website and redirects the user to the entity provider.
Auto-Provision Users – By default, your institution will create users and edit them through the web portal even when using SSO. The Auto-Provision Users option allows the SSO workflow to create a user automatically. For this to work properly, the entity provider must supply a first name, last name, and email for users. Upon creation, user roles will correlate with the UserRoles listed in the SAML assertion, but if none are specified, the user will have no roles when created this way. For a list of UserRoles and what they do, please see the following article: https://get.truechecks.support/hc/en-us/articles/226377888-Managing-TrueChecks-Users
Notably, if auto-provisioning is enabled and a SAML assertion with no User Roles is sent, it will wipe out the user roles on the TrueChecks side, so it is important to include this field with accurate user roles.
Additionally, if Auto-Provision Users is enabled but Force SSO is not, a user will be created with a temporary password on the portal. For them to update their credentials and log in, a one-time password reset will be required at that point.
If you or your team have any questions or comment, please email Advanced Fraud Solutions Support at support@advancedfraudsolutions.com or call 1-866-663-4709 Option 2.
Comments
0 comments
Please sign in to leave a comment.