Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Identity Provider (IdP) Management

Overview

Users with the Security Admin role will be able to modify existing Identity Provider (IdP) configurations and set up secondary providers. This feature allows you to take control of your integration(s) and easily perform maintenance such as updating certificates and secrets. Many organizations will only have a single identity provider, but some organizations may require additional providers for different sets of users, where users from both providers require access to Conga software. Commonly, business partners may use a directory or identity system that is partitioned from the one supporting first-party corporate users, or development and testing identities are isolated from production.

  1. Log in to the Application Portal.
  2. Using the top navigation bar, open the ADMIN menu and select Global Settings.
  3. Select the Identity Providers tab.
  4. The existing provider(s) will appear in a view similar to the page shown below. The entries under NAME and TYPE may vary.

METADATA IMPORT (SAML-BASED PROVIDERS ONLY)

Optionally, the Application Portal can conveniently import most settings from SAML metadata (XML) generated by your identity provider.

  1. Obtain the XML metadata from your identity provider. Please refer to your vendor's instructions if necessary.
  2. In the portal's provider configuration tab, click the Upload Metadata button.
  3. Browse to or drop the file into the pop-up dialog, then click Upload.

The screen will update the relevant settings with values found within the uploaded metadata. Note that previous settings (if any) will be overwritten when the metadata contains a value for those settings. Commonly, there are some settings which are not provided by the XML metadata; these settings will not be modified and will retain their prior values. Please double-check all settings for accuracy.

Signing Certificate Replacement/Rotation (SAML-based providers only)

During initial configuration, at least one signing certificate must be configured. Your company's policies may require the signing keys to be rotated or changed on occasion. the Application Portal supports zero downtime rotation of your SAML identity provider's signing certificates when you follow these steps to upload the new certificate before applying it to the identity provider. When more than one certificate is configured, Conga will accept SAML assertions that are verified with digital signatures matching either certificate.

  1. Scroll down to the Security/Certificates section.
  2. Paste your new or updated certificate; it must be in PEM text format, including the lines indicating BEGIN and END of the certificate.

  3. Do not remove the old certificate until testing has confirmed that the new certificate is working correctly.
  4. Follow the steps indicated in the Saving and Testing Changes section of this document (above).
  5. Once everything is working as expected using the new certificate, use a similar procedure to remove the old certificate.

Enable/Disable Single Logout (SLO)

As a security best-practice, when a user explicitly requests to sign out, it is recommended that the user be signed-out of all applications and systems sharing a common session with the identity provider. This behavior is recommended by Conga and is enabled by default, when available (SLO must be supported by the identity provider to work correctly). This behavior does not apply to users whose sessions time-out or otherwise expire without an explicit user action.

When a user initiates a logout from a Conga application, all Conga sessions will be invalidated. Likewise, if an identity provider issues a valid SLO request to Conga, the Conga sessions will be terminated. (These behaviors are not configurable.) However, there may be reasons why users directly signing out of Conga should not be signed out of all other (non-Conga) applications sharing the same identity provider.

As an administrator, you can disable single log-out (SLO) in the provider's configuration settings. Users will not be redirected to the provider's SLO flow and, instead, they will be presented with a Conga login page (or a configurable alternate URL of your choice).



Saving and Testing Changes

  1. Once all configuration settings changes are completed, scroll to the bottom of the Configuration tab and click Save Changes.
  2. If there are any validation errors, a banner appears near the top of the window and the relevant fields are highlighted in red. Please correct the problem(s) and try again.
  3. On success, the following notice dialog will appear:

    Since establishing a trust with an identity provider involves two different systems, the validation performed by Conga cannot confirm that all corresponding settings are correct on the provider side. Administrators must perform the following test procedures without closing the current browser tab or window.

  4. Required test procedure:
  1. Leave the current browser window and tab open. Do not log out of any application (Conga or non-Conga) that relies on the same identity provider.
    1. You must complete this procedure before your current session times out.
  2. Open a private (incognito) browser window, or use a completely different browser (e.g. Firefox instead of Chrome) or computer, so that the test is performed in isolation.
  3. In the new/private window, navigate to the Application Portal and sign in using the identity provider whose settings were changed in the original window.
  4. Only if you are able to successfully log in and have the expected set of privileges, display name, etc., then return to the original window and click Keep Changes.
  5. Otherwise, return to the original window and click Revert Changes to overwrite the configuration with the previous settings. Make corrections, then try again.

Username Formats Tab

The Application Portal requires knowledge of your users' standard username format, so that it can identify users attempting to access your company's accounts and direct them to the appropriate identity provider.

Conga recommends using an e-mail style username, where your user identifiers are suffixed by the '@' symbol followed by a fully qualified domain name owned by your organization. It is not required that an e-mail style username format resolve to a real, working e-mail inbox. When configuring multiple Conga environments or multiple Identity Providers to support production and pre-production use cases, Conga recommends using the following alternative formats, where example.com is replaced by your organization's domain:

ENVIRONMENT NAME/PURPOSESUGGESTED USERNAME FORMAT
Sandbox@example.com/sandbox
Test@example.com/test
Production@example.com

Restrictions:

  • Each provider should have at least one(1) username format defined.
  • Each provider may have a maximum of two(2) email-style entries and two(2) windows-style entries.
  • Each username format must be globally unique.

Add a New Username Format

  1. Within the Username Formats tab, start by selecting the format type: Email or Windows Domain.
  2. Enter the domain portion of the username format to complete the example.
  3. Click Add to List.
  4. If validation checks pass, the new username format will appear in the list and it is saved immediately.