NOTE: This authentication module is available if the Configuration Module is installed.
The authentication module supports authentication by web single sign-on solutions that work with a proxy-based architecture.
| 
 Credentials  | 
 Identity's central user account or personnel number.  | 
| 
 Prerequisites  | 
  | 
| 
 Set as default  | 
 No  | 
| 
 Single sign-on  | 
 Yes  | 
| 
 Front-end login allowed  | 
 No  | 
| 
 Web Portal login allowed  | 
 Yes  | 
| 
 Remarks  | 
 You must pass the user (in the form: UserName =<user name of authenticated user>) in the HTTP header. The identity found in the One Identity Manager database has the central user account or personnel number that matches the given user name. If an identity has a main identity or several subidentities, the QER | Person | MasterIdentity | UseMasterForAuthentication configuration parameter controls which identity is used for authentication. 
 NOTE: Identities that are classified as a security risk are no longer be able to log in to One Identity Manager. To allow login, set the QER | Person | AllowLoginWithSecurityIncident configuration parameter. The user interface and permissions are loaded through the system user that is directly assigned to the logged in identity. If a system user is not assigned to the identity, the system user from the SysConfig | Logon | DefaultUser configuration parameter is used. Changes to the data are assigned to the logged in identity.  |