Enabling AR authentication for bypassing other authentication methods


As a BMC Helix Single Sign-On administrator, you can enable AR authentication to bypass other authentication methods configured for a realm. This feature might be useful to you if you want to provide an ability for administrator users to bypass the primary authentication (for example, SAML), and log in to applications protected by BMC Helix SSO via AR authentication.

Related topic

Before you begin

Ensure that you have obtained the following information from the Action Request System (AR System) administrator:

  • Host name of the server where AR System is installed.
  • Port number of AR System.

To enable bypassing of other authentication methods

  1. In the BMC Helix SSO Admin Console, select any realm with any authentication type except AR or Local. 
  2. Select the Enable AR authentication for bypass, and then click the AR tab.
  3. Enter the host name and port of the AR System server.
  4. Click Test to verify the connection works.
  5. Click Save.

When you have enabled AR authentication for bypassing other authentication methods, to get authenticated against AR System, existing AR System end users can log in to their applications by using the following URL: http://<host_name>:<port_number>/rsso/start?bypass-auth=true&tenant=<realmId>&goto=<application_url>, where <application_url> is the URL of the application that the users want to access. Example of <application_url>: http://clm-aus-012345.bmc.com:6789/dwp/ for BMC Helix Digital Workplace. Each application has own URL. 

To specify IP addresses for the AR bypass functionality

By default, the AR bypass functionality authenticates all the IP addresses. However, you can use the bypass functionality for specific IP addresses. 

To do this, perform the following steps:

  1. Log in to the BMC Helix Single Sign-On admin console.
  2. In the Realms tab, edit the required realm.
  3. In the Authentication tab, click AR.
  4. In the Allowed IP Range(s) field, add the IP addresses that the AR bypass functionality should bypass.
  5. Click Save.

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*