# AM

Access Management & SSO

# Create identities (manually, CSV file, or authoritative source)

{{@718}}

# Add applications

## Description

This wizard allows you to add a new Service Provider, that is, to configure an application that relies on an Identity Provider (IdP) to authenticate users and provide access to its services.

To be able to add new applications (SP), you must install the Federation Addon.

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Add application* option, Soffid will require to **install the Federation Addon**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/aJAQxBVokVmm6ZZX-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/aJAQxBVokVmm6ZZX-image.png)

When you click the OK button, Soffid will browse to the Soffid Download Area where you can find the Federation Addon. To install Federation Addon you can follow the steps [How to install Federation in Soffid?](https://bookstack.soffid.com/books/federation-guide/page/how-to-install-federation-in-soffid)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Once you select the *Add applicatio*n option, Soffid will display the wizard to register the Identity Provider, if it does not exist previously.

[![image-1706615738719.png](https://bookstack.soffid.com/uploads/images/gallery/2024-01/scaled-1680-/image-1706615738719.png)](https://bookstack.soffid.com/uploads/images/gallery/2024-01/image-1706615738719.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>You must select the application you want to add.

[![image-1678779815350.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678779815350.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678779815350.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1. </span>Soffid app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.1. </span>The Finish step will be displayed.

[![image-1678779871340.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678779871340.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678779871340.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.1.1. </span>If you click the Finish button, Soffid will display the Service Provider page.

[![image-1677671303079.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677671303079.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677671303079.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2. </span>AWS app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.1 </span>Soffid will download the proper certificate.

[![image-1677672235598.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672235598.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672235598.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.2 </span>Once, you download the certificate, Soffid will display the Configure application step. You must follow the indicated steps at this point and click the Next button.

[![image-1677672319865.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672319865.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672319865.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.2.2 </span>Then, you must upload the metadata of your service provider and click the Finish button.

[![image-1677672438056.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672438056.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672438056.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3. </span>Google workplace app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.1 </span>Soffid will download the proper certificate.

[![image-1677672235598.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677672235598.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677672235598.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.2 </span>Once, you download the certificate, Soffid will display the Configure application step. You must follow the indicated steps at this point, fill in the Domain, and click the Next button.

[![image-1677682975815.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677682975815.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677682975815.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.3 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.3.4 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677683851230.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683851230.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683851230.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4. </span>Microsoft 365 app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.1. </span>When you select this option, Soffid will display the Configure application step. You must follow the indicated steps at this point, and click the Next button.

[![image-1677683934770.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683934770.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683934770.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.2 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.4.3 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677684047850.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684047850.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684047850.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5. </span>OpenID app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.1. </span>When you select this option, Soffid will display the Configure application step. You must configure your Service Provider, and click the Next button.

[![image-1677684651700.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684651700.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684651700.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.2. </span>Then Soffid will return you the Client id and Client secret

[![image-1677684676985.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684676985.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684676985.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.3 </span>Then, you must click the Finish button.

[![image-1677683080657.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677683080657.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677683080657.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.4 </span>Finally, Soffid will browse to the Service Provider page where you can finish the Service provider configuration.

[![image-1677684869231.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677684869231.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677684869231.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.6. </span>SAML 2.0 app:

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.6.1 </span>Soffid will download the metadata XML file.

[![image-1677686059860.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686059860.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686059860.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.2 </span>Once, you download the metadata file, Soffid will display the steps to follow.

[![image-1677686120040.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686120040.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686120040.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3.5.3 </span>Then, you have to upload the metadata file generated by the Service Provider

[![image-1677686216222.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1677686216222.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1677686216222.png)

# Create MFA policies

## Description

This wizard will help you to configure multi-factor authentication in order to expand security. This process requires users to provide two or more forms of identification before being granted access to a system or application.

<p class="callout info">For more information, you can visit [the Two-factor authentication (2FA) book](https://bookstack.soffid.com/books/two-factor-authentication-2fa-VsJ).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Create MFA policies* option, Soffid will require to **install the Federation and the OTP Addons**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/9gfTecsUY1WjDknX-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/9gfTecsUY1WjDknX-image.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>Frist, you must select the authentication factor to use

[![image-1677146953516.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677146953516.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677146953516.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Second, you must select the delivery method to use. If you select the second option, you have to select the users to whom the instructions will be sent.

[![image-1677147051712.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147051712.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147051712.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">4. </span>Next, you must select which users will have the second authentication factor activated.

[![image-1677147755823.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147755823.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147755823.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">5. </span>Finally, the changes will be applied and the process will be finished.

[![image-1677147905326.png](https://bookstack.soffid.com/uploads/images/gallery/2023-02/scaled-1680-/image-1677147905326.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-02/image-1677147905326.png)

# Create adaptive authentication rules

## Description

Adaptive authentication rules are a set of security policies and mechanisms that adjust authentication requirements. These rules determine the strength of authentication required for each user, based on factors such as their location, device, past login behavior, and other risk indicators.

<p class="callout info">For more information, you can visit the [Condition for Adaptive authentication page](https://bookstack.soffid.com/books/federation/page/condition-for-adaptive-authentication).</p>

## Step-by-step

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">1. </span>If you have not previously installed the Federation Addon, the first time you select the *Create MFA policies* option, Soffid will require to **install the Federation and the OTP Addons**.

[![image.png](https://bookstack.soffid.com/uploads/images/gallery/2025-02/scaled-1680-/Hrp87gsNIs26JsAl-image.png)](https://bookstack.soffid.com/uploads/images/gallery/2025-02/Hrp87gsNIs26JsAl-image.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">2. </span>You must select the *Create adaptive authentication rules* and then click the Ok button.

[![image-1678097740662.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678097740662.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678097740662.png)

<span style="color: #a6d100; font-weight: bold; font-size: 18px;">3. </span>Then, Soffid will browse to the Adaptive authentication window, where you could configure it

[![image-1678098184254.png](https://bookstack.soffid.com/uploads/images/gallery/2023-03/scaled-1680-/image-1678098184254.png)](https://bookstack.soffid.com/uploads/images/gallery/2023-03/image-1678098184254.png)