Users Guide

Table Of Contents
NOTE:
To perform any tasks on OpenManage Enterprise, you must have the necessary user privileges. See Role and scope-
based access control in OpenManage Enterprise on page 15.
Only a maximum of four OpenID Connect provider IDs can be added in the appliance.
Post upgrade of OpenManage Enterprise from version 3.5 or earlier, the AD/LDAP and OIDC (PingFederate or
KeyCloak) device managers would need to recreate all the previous-version entities as these entities are only available to
the administrators post upgrade. For more information, see the Release Notes at https://www.dell.com/support/home/
en-yu/product-support/product/dell-openmanage-enterprise/docs
Prerequisites:
Before enabling an OpenID Connect provider login you must:
1. Add an OIDC provider in the OpenManage Enterprise: In OpenManage Enterprise Application Settings, add an OpenID
Connect provider. When you add the OpenID Connect provider, a Client ID is generated for the OpenID Connect provider.
For more information, see: Add an OpenID Connect provider to OpenManage Enterprise on page 152.
2. Configure the OpenID Connect provider using the Client ID: In the OpenID Connect provider, locate the Client ID and
define a login role (Administrator, Device Manager or Viewer) by adding and mapping the scope called dxcua (Dell extended
claim for user authentication). For more information, see:
Configure an OpenID Connect provider policy in PingFederate for role-based access to OpenManage Enterprise on page
153
Configure an OpenID Connect provider policy in Keycloak for role-based access to OpenManage Enterprise on page 154
When you add an OpenID Connect provider in OpenManage Enterprise, it is listed on the Application Settings > Users >
OpenID Connect Providers page. The following OIDC provider details are displayed:
Name - The OpenID Connect provider's name when it was added in the appliance
Enabled - A 'check' on this field indicates that the OpenID Connect provider is enabled in the appliance
Discovery URI - The URI (Uniform Resource Identifier) of the OpenID Connect provider
Registration Status - Can be one of the following:
Successful - Indicates a successful registration with the OpenID Connect provider
Failed - Indicates an unsuccessful registration with the OpenID Connect provider. The 'Failed' OpenID Connect provider
registration will not be allowed even when they are enabled.
In Progress - This status is displayed when the appliance tries to register with OpenID Connect provider.
On the right pane, Client ID, Registration Status, Discovery URI are displayed for the selected OpenID Connect provider. You
can click See details to view the certificate details of the OpenID Connect provider.
On the Application Settings > Users > OpenID Connect Providers page you can do the following:
Add an OpenID Connect provider to OpenManage Enterprise on page 152
Edit an OpenID Connect provider details in OpenManage Enterprise on page 154
Test the registration status of OpenManage Enterprise with the OpenID Connect provider on page 154
Enable OpenID Connect providers on page 155
Disable OpenID Connect providers on page 155
Delete OpenID Connect providers on page 155
Add an OpenID Connect provider to OpenManage Enterprise
Adding, enabling, and registering an OpenID Connect provider (Keycloak or PingFederate) allows for an authorized client login to
OpenManage Enterprise. This generates a Client ID.
To add an OpenID Connect provider to OpenManage Enterprise, go to the Application Settings > Users > OpenID Connect
Providers page and do the following:
NOTE: Only a maximum of four OpenID Connect provider clients can be added.
1. Click Add to activate the Add New OpenID Connect Provider page.
2. Fill the following information in the respective fields:
a. Name - Name for the OIDC client.
b. Discovery URI - Uniform Resource Identifier of the OIDC provider
c. Authentication type - Choose from one of the following methods the access token must use to access the appliance:
i. Initial Access Token - Provide the Initial access token
ii. Username and Password - Provide the username and password
152
Managing OpenManage Enterprise appliance settings