This documentation supports the 22.1 version of BMC Helix Single Sign-On, which is available only to BMC Helix customers (SaaS).
To view an earlier version, select the version from the Product version menu.
As an administrator in the BMC Helix SSO Admin Console, you can have one of the following roles: SaaS administrator users have full rights to create, activate, delete, or temporarily deactivate other tenants. Users with this role can view and change the configuration of any tenant registered on the BMC Helix SSO server. From the SaaS tenant, SaaS administrators can create other SaaS administrator users. From a customer tenant, SaaS administrators can create tenant administrator users. Tenant administrator users have full rights to manage local users for realms in their tenant. Starting from Helix SSO 21.3 release, Tenant administrators can perform the following actions in the BMC Helix SSO Admin Console: Starting from Helix SSO 22.1 release, Tenant administrators have access to edit OAuth2 settings in the BMC Helix SSO Admin Console.Role Description SaaS administrator Tenant administrator
Depending on your role, you have the following permissions for accessing features in the BMC Helix SSO Admin Console:
Feature in the BMC Helix SSO Admin Console | SaaS administrator | Tenant administrator | Reference |
---|---|---|---|
BMC Helix SSO server configuration | Supported | Not supported | Configuring the BMC Helix SSO server |
BMC Helix SSO server configuration import and export | Supported | Not supported | Exporting and importing BMC Helix SSO server configuration |
Realms management | Supported | Partially supported | Adding and configuring realms |
User sessions management | Supported | Partially supported | Invalidating and configuring end user sessions |
Local users management | Supported | Partially supported | Configuring Local authentication |
OAuth 2.0 clients management | Supported | Not supported | Configuring OAuth 2.0 |
LaunchPad applications management | Supported | Not supported | Adding applications to the Digital Service Management page |
Administrator users management | Supported | Not supported | Setting up BMC Helix SSO administrator accounts |
Tenant management | Supported | Not supported | Activating tenants |
You can create administrator users who have access and perform tasks in the BMC Helix SSO Admin Console by one of the following methods:
After the SaaS administrator logs in to the BMC Helix SSO server for the first time as the default administrator, the SaaS administrator can change the default password. For details about how to do this, see Setting up BMC Helix SSO administrator accounts.
SaaS administrators can create the following users in the BMC Helix SSO Admin Console from the Admin User tab.
For information about how to create users, see Setting up BMC Helix SSO administrator accounts.
To distribute responsibility between BMC Helix SSO administrators, a SaaS administrator can grant administrator privileges to users from an external LDAP directory. External users can log in to the BMC Helix SSO Admin Console, and perform administrative tasks available to them.
To grant the SaaS administrator privileges to external users, in the SaaS tenant, a SaaS administrator must configure the LDAP authentication on the Server Configuration page in the BMC Helix SSO Admin Console.
To grant the tenant administrator privileges to external users, in a customer tenant, a SaaS administrator must configure LDAP authentication on the Server Configuration page in the BMC Helix SSO Admin Console. For instructions on how to configure LDAP for external users, see Configuring authentication for BMC Helix SSO administrators.
Important
External users with administrator privileges in BMC Helix SSO follow the password policies enforced by LDAP.