Configure an authentication method
Use the Authentication page to select and configure an authentication method to verify the identity of anyone who wants to connect to Webex WFO. Webex WFO supports three methods of authentication: Default Webex WFO Authentication, SAML Authentication, and Active Directory Authentication. On the Authentication page, you can configure and enable the default authentication method and the SAML authentication method. You can enable and configure the Active Directory authentication method only for on-premises deployments of Webex WFO on the Active Directory Configuration page, located under Application Management > Global > System Configuration > Active Directory Configuration.
NOTE Both the system administrator and the tenant administrator can configure SAML authentication for a particular tenant. If both administrators configure tenant-level SAML authentication for a particular tenant, Webex WFO uses the most recent configuration.
If your system administrator enables system-wide SAML authentication, the tenant-level SAML authentication settings are overridden.
Webex WFO allows for mixed-mode authentication. This means you can enable multiple user-authentication methods simultaneously.
Prerequisites
You must have tenant permissions to configure and enable authentication.
Before you configure SAML authentication, configure an identity provider (IdP) that supports SAML 2.0. When you configure the IdP, make sure you record the Issuer ID, the Single Sign On URL, and the Identity Provider Certificate and then store this data in an easy-to-access location. You use this information when you configure SAML authentication.
NOTE Select and configure Okta or Active Directory Federation Services (ADFS) as your identity provider to authenticate user names and passwords for Webex WFO (the service provider).
Page location
Application Management > Global > Administration > Authentication
Procedures
You can use the Authentication page to enable/disable Webex WFO authentication or to enable/disable and configure SAML authentication. With Webex WFO, you can enable multiple user-authentication methods simultaneously.
Enable default Webex WFO authentication
Webex WFO authentication is enabled by default. This means user authentication and passwords are managed using Webex WFO. In systems that sync with an ACD, users are created and managed in the ACD, although you can still create users in Webex WFO.
For system administrators, this selection is read-only.
Enable Webex WFO authentication
- Select Enable Webex WFO Authentication.
- Click Save.
Disable authentication
- Select the authentication method you want to disable.
One authentication method must be enabled before you can click Save. To disable Webex WFO Authentication, you must first select SAML Authentication. - Click Save.
Configure SAML authentication using Okta as the IdP
Before performing this procedure, verify that you have configured Okta as the IdP. See.
- Select Enable SAML Authentication.
- In the Identity Provider section, use the data you collected when you configured Okta as your IdP to configure the following fields.
- Enter a unique name for this IdP configuration in the NAME field.
- Enter the ISSUER ID. Paste the URL from the Identity Provider Issuer field in Okta.
Enter the SINGLE SIGN ON URL. Paste the URL from the Identity Provider Single Sign-On URL field on Okta.
NOTE This URL is provided by the IdP and is not the same as the Single Sign On URL supplied by Webex WFO under Service Provider.
- Import the IDENTITY PROVIDER CERTIFICATE.
- Click Import the certificate that you downloaded from the X.509 Certificate field in Okta.
- (Optional) Click Export to export an existing certificate.
- (Optional) Click View Details to view the details of the certificate.
- (Optional) In the Service Provider section, the following steps are optional. Okta does not require a service provider certificate or private key.
- Select Use Tenant Name in Entity ID to prepend the name of the tenant to the tenant’s public host name in the Entity ID.
- Select the SAML Signature Algorithm.
- Select the SAML Digest Algorithm.
- (Optional) To opt out of signing the SAML token, clear the Sign SAML Response check box.
- Import the SERVICE PROVIDER CERTIFICATE. You can use the default global certificate provided by Webex WFO (cloud deployments only) or upload a self-managed certificate and private key.
-
- Import — Navigate to the self-managed service provider certificate that you want to import into Webex WFO.
- Export — Exports your current service provider certificate.
- View Details — Shows the details of the current service provider certificate: Issuer, Subject, Start Date, and End Date.
- Export Metadata — Exports the metadata for the current service.
- Import the PRIVATE KEY. The private key for a self-managed service provider certificate.
- Click Save.
NOTE Webex WFO is the service provider, and the Authentication URL, Entity ID, and Single Sign On URL are read-only fields.
Configure SAML Authentication using ADFS as the IdP
Before performing this procedure, verify that you have configured ADFS as the IdP.
- Select Enable SAML Authentication.
- In the Identity Provider section, use the data you collected when you configured ADFS as your IdP to configure the following fields.
- Enter a unique name for this IdP configuration in the NAME field.
- Enter the ISSUER ID. This is normally structured in the following way:
https://<Active Directory domain name>/adfs/services/trust
Enter the SINGLE SIGN ON URL. This is normally structured in the following way:
https://<Active Directory domain name>/adfs/ls
NOTE This URL is provided by the IdP and is not the same as the Single Sign On URL supplied by Webex WFO under Service Provider.
- Import the IDENTITY PROVIDER CERTIFICATE.
- Under Identity Provider Certificate, click Import.
- Navigate to the identity provider certificate you exported when you configured ADFS, and then select it.
- Click Open.
- (Optional) Click Export to export an existing certificate.
- (Optional) Click View Details to view the details of the certificate.
- In the Service Provider section, perform the following steps:
NOTE Webex WFO is the service provider, and the Authentication URL, Entity ID, and Single Sign On URL are read-only fields.
- (Optional) Select Use Tenant Name in Entity ID to prepend the name of the tenant to the tenant’s public host name in the Entity ID.
- Select the SAML Signature Algorithm.
- Select the SAML Digest Algorithm.
- (Optional) To opt out of signing the SAML token, clear the Sign SAML Response check box.
- Import the SERVICE PROVIDER CERTIFICATE. You can use the default global certificate provided by Webex WFO (cloud deployments only) or upload a self-managed certificate and private key.
- Import — Navigate to the self-managed service provider certificate that you want to import into Webex WFO.
- Export — Exports your current service provider certificate.
- View Details — Shows the details of the current service provider certificate: Issuer, Subject, Start Date, and End Date.
- Export Metadata — Exports the metadata for the current service.
- Import the PRIVATE KEY. The private key for a self-managed service provider certificate.
- Click Save.