The [whitelist source=user_list] section allows whitelisting users based on a User List policy configured in SPS (Policies > User Lists). To enable this whitelist, configure one of the use cases below.
NOTE: The user names are compared to the User List in a case-sensitive manner.
For details on creating user lists, see "Creating and editing user lists" in the Administration Guide.
| Type: | string | 
| Required: | no | 
| Default: | N/A | 
Description: The name of a User List policy containing gateway users configured on SPS (Policies > User Lists). You can use this option to selectively require multi-factor authentication for your users (for example, to create break-glass access for specific users).
To allow specific users to connect without providing credentials, the User List policy should have the following settings:
To enforce authentication for selected users, the User List policy should have the following settings:
The [whitelist source=ldap_server_group] section allows whitelisting users based on LDAP Server group membership. To enable this whitelist, configure one of the use cases below.
NOTE: The user names and groups are compared in LDAP in a case-insensitive manner.
[whitelist source=ldap_server_group] allow=<no_user-or-all_users> except=<group-1>,<group-2>
| Type: | string (all_users | no_users) | 
| Required: | no | 
| Default: | N/A | 
Description: This parameter defines whether to allow all users or no user to connect without providing credentials. Used together with the except parameter, you can define specific LDAP/AD group(s) that are exempt from this rule.
| Type: | string | 
| Required: | no | 
| Default: | N/A | 
Description: This parameter defines those specific LDAP/AD group(s) that are exempt from the rule defined by the allow parameter.
To allow members of specific LDAP/AD group(s) to connect without providing credentials, type the names of these LDAP/AD groups as values of the except parameter and set the allow parameter to no_user:
[whitelist source=ldap_server_group] allow=<no_user> except=<group-1>,<group-2>
You must configure the name of the LDAP Server policy in the [ldap_server] section.
To enforce authentication only on members of specific LDAP/AD group(s), type the names of these LDAP/AD groups as values of the except parameter and set the allow parameter to all_users:
[whitelist source=ldap_server_group] allow=<all_users> except=<group-1>,<group-2>
You must configure the name of the LDAP Server policy in the [ldap_server] section.
By default, SPS assumes that the external identity of the user is the same as the gateway username (that is, the username the user used to authenticate on SPS during the gateway authentication). If there was no gateway authentication, then the server username is used for authentication.
You can use the following methods:
Explicit mapping: [usermapping source=explicit]
LDAP server mapping: [usermapping source=ldap]
To look up the external identity of the user from an LDAP/Active Directory database, configure the [usermapping source=ldap_server] section of the SPS plugin.
The Explicit method has priority over the LDAP server method.
If you have configured neither the append_domain parameter nor any of the [USERMAPPING] sections, SPS assumes that the external identity of the user is the same as the gateway username.
To map the gateway user name to an external identity, configure the following name-value pairs.
| Type: | string | 
| Required: | no | 
| Default: | N/A | 
Description: To map the gateway user name to an external identity, configure the name-value pairs in the following way:
Type the gateway user name instead of <example-user-1>.
Type the external ID instead of <ID-1>.
NOTE: Use this option only if there are not only a few users, or for testing purposes. If there are too many users, it can cause performance issues.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. 이용 약관 개인정보 보호정책 쿠키 기본 설정 센터