SSO Configuration

Modified on Wed, 8 May at 10:09 AM

In iCFM, you can use Single Sign-On (SSO) to log in with credentials from Azure Active Directory, Okta, or JumpCloud. Please Note that users must exist on both iCFM and the chosen platform with the same email/username.


Access SSO Configuration:

  1. Menu > Admin Options
  2. Open SSO Configuration (must be Super User)
  3. Choose Azure Active Directory, Okta, or JumpCloud to reveal the input fields
  4. Follow the SSO Integration steps below for each provider*
  5. Return to iCFM, input the Client ID, Client Secret, Tenant ID, and URL, as required
  6. Click Save Configuration


*Azure Active Directory:

  1. Create a new app in Azure Portal (Azure Active Directory > App registrations > New registration). Name it "CETA Cloud". (Azure Help Center)
  2. Register a Redirect URI (e.g. https://{client-name}.cetacloud.tv/login/azure/callback)
  3. Check API Properties

    (In the Application "API Properties" please make sure you add these *configured* permissions, and check the box that says there is consent for your company.  See image below.  Note: You may have to wait a few minutes for the settings to propagate)

  4. Copy the Application (client) ID, Client Secret, and Tenant ID from the Overview and Certificates & secrets tabs


*Okta: 

  1. Create a new OIDC app in Okta Developer Console (Applications > Create App Integration > OIDC - OpenID Connect > Web Application). Name it "CETA Cloud". (Okta Help Center)
  2. Define Base and Login redirect URIs (e.g. https://{client-name}.cetacloud.tv and https://client-name.cetacloud.tv/login/okta/callback)
  3. Copy the Client ID, Client Secret, and Org URL


*JumpCloud:

  1. Create a new OIDC app in JumpCloud Admin Portal (User Authentication > SSO > + Configure New > Custom OIDC App). Name it "CETA Cloud". (JumpCloud Help Center)
  2. Define a Redirect URI (e.g. https://{client-name}.cetacloud.tv/login/jumpcloud/callback)
  3. Copy the Client ID and Client Secret from the Settings tab



CETA iCFM Built-in Two-Factor Authentication (2FA): As an added layer of security, CETA iCFM provides a built-in Two-Factor Authentication (2FA) system. Users can choose to enable this feature for their accounts, requiring them to authenticate their identity through a second method, in addition to their password.


Please Note: We still support legacy LDAP integration if required. Please Contact CETA with LDAP Server details (host IP, dn, port, suffix, search_attribute) to enable Active Directory (LDAP). After successful configuration, users can log in to CETA iCFM using their SSO credentials.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article