Workflow
- Last UpdatedMay 11, 2026
- 2 minute read
There are several different scenarios for configuring a federated identity provider on a machine. The following list provides a detailed explanation of different the federated identity provider plugin workflows:
-
If the earlier version of System Platform is already installed on the machine, the plugin cannot be configured, and the following error message is displayed.
"Use the Authentication Plugin provided by System Platform instead to configure Federated Identity provider".
-
If there is no System Platform installed or the installed version is different from 2023 and the System Management Server (SMS) or Redundant SSO (RSSO) node has not been configured, then the following notification message is displayed.
"The Machine is not configured as System Management Server (SMS) or RSSO Node".
-
If a System Management Server (SMS) or Redundant SSO (RSSO) node has been configured and there is no System Platform installed or the installed version is lower than 2023, then the following three configuration options are displayed.
-
None: This option allows you to configure and deletes all other providers.
-
Microsoft Entra ID: You are required to enter all required fields and then will be able to select a configure option; the action saves the Microsoft Entra ID provider and deletes any other provider configured.
-
CONNECT: When you select this option, the CONNECT sign in page is displayed to fill in the credentials on the AVEVA domain. Once you enter the correct credentials and accept the multi-factor authentication challenge, the sign in page closes.
To perform this operation, "Application Manager" permissions are required in CONNECT.
-
-
If the process is executed correctly, then endpoint, client id, and service endpoint is displayed inside the Configuration Messages section; the last step of the action deletes any other previously configured provider.
Note: This workflow is applicable only for configuring Microsoft Entra ID as the federated identity provider.