Single Sign-On with Water Loss or Water Simulation and OMI Web
- Last UpdatedMay 28, 2024
- 2 minute read
The AVEVA Identity Manager (AIM) is a standalone authentication server that allows users to log into AVEVA products using a standard user experience.
AVEVA Identity Manager is installed as a prerequisite for AVEVA System Platform, and it is a PCS framework core service and acts as a local identity provider for all on prem products, and it makes use of the industry standard OpenID Connect protocol.
Water Loss (WL) and Water Simulation (WS) can be configured to login through AIM for a SSO experience when their web interfaces are embedded in OMI Web.
Note: SSO is not supported when Water Loss or Water Simulation web interface is embedded in OMI Desktop.
Configure AVEVA Identity Manager
Before you configure AVEVA Identity Manager (AIM), the System Management Server (SMS) must be configured via the Configurator utility.
On the System Management Server (SMS) host, start the Configurator and make sure the settings for the web client are correct:
-
Under Common Platform, ensure there is a green checkmark next to System Management Server. If not, select System Management Server and select the option to make this host the SMS.
-
Select System Management Server, then select Advanced.
-
Select the Ports tab and ensure the HTTPS Port is set to 443.
-
Select OK.
-
-
Under AVEVA System Platform, ensure there is a green checkmark next to Identity Manager Registration. If not, follow the steps below:
-
Select Identity Manager Registration.
-
Select Configure.
-
Select Close
Note: If the SMS was not already defined after performing the above steps, go to the other nodes that have System Platform installed. Use the Configurator to connect them to the SMS.
-
There are three provider options for AIM:
-
None: You can use local Identity Providers such as windows authentication or product-specific security. In this mode, AIM can authenticate Operating System (OS) users.
-
Azure AD: User accounts configured in Azure AD can be used for authentication.
-
CONNECT. User accounts configured in CONNECT can be used for authentication.
For more information refer to AVEVA Identity Manager Help.