
SANGFOR IAM v2.1 User Manual
156
You can choose the needed one according to your case. As to the configuration of third-party
authentication server, please refer to Section 7.3 Authentication Server.
[Add to Organization Structure]: Check the option [Automatically add authenticated new users to
the above group], and the applicable new users will be added to the assigned structure group and
entitled with all the privileges of this structure group.
Except the above configurations, you can have the successfully-authenticated new users‟ IP
address, MAC address, or both the IP and MAC address automatically bound; or neither of the IP
or MAC address automatically bound.
Enabling policy authentication for new users can have the IP addresses of different segments
get authenticated differently, and add the user to the corresponding user group, and apply its
individual access control policy.
Taking the IP address as user name or taking host name as the user name requires the IAM
gateway device binding at least with one IP address or MAC address of the user.
If the IAM gateway device fails to resolve the host name because of the existence of the
firewall on the client side, this host will be not added to the user list, but it will be entitled
with all the privileges of its root group or the assigned user group (if it had been successfully
added to certain user group).
7.2.2.
SSO Settings
Single Sign-On (SSO) will not require the user for username and password once again after its
first logon, but have the user automatically get passed when it logs in to the third-party
authentication server.
The user need type only once the login password to log in to the third-party authentication server,
automatically passing the authentication instead of typing password once again next time;
therefore, it can lower the risk of password being disclosed.
[SSO Settings] covers the options for single sign-on, including POP3 SSO, Web SSO and Proxy