Identity provider connections

An Organization administrator role is required. For information, see User roles.

Identity provider connections define the sign-in methods users can use to authenticate to Nintex. You can create and manage multiple identity provider connections for your organization, and assign active connections to environments to make them available as sign-in options.

Creating a connection does not make it available to users. To show a connection on the sign-in page, assign it to an environment.

Important: 
  • In the Organization portal, an environment is a Nintex Workflow tenant.
  • Identity provider connections are created for the organization and assigned to environments to control where users can sign in with each connection.

What is an identity provider connection?

An identity provider connection represents a sign-in method. It connects Nintex to an authentication service that validates user credentials.

An identity provider connection is also a sign-in method. The connection controls how users authenticate, while the environment assignment controls where users can use that connection to sign in.

The authentication service can be:

  • Managed by Nintex

  • Managed by your organization

  • Managed by a third-party provider, such as Microsoft Entra ID or Okta

After you configure an identity provider connection and assign it to an environment, users can sign in using that connection.

Connection types

The Nintex Platform supports the following types of identity provider connections:

  • SAML-based identity provider: Allows users to sign in using single sign-on (SSO) through an identity provider such as Microsoft Entra ID, Okta, Active Directory Federation Services, or another SAML provider.

  • Nintex: Allows users to sign in using Nintex authentication. This includes the username and password connection created when the organization is first set up. It also includes the Nintex External Users connection as well as the One Time Password (OTP) connection.

Note: 
  • The username and password connection cannot be added manually. It is created when the organization is first set up.
  • Only users invited as Nintex External Users can sign in using the Nintex External Users connection. Users invited as identity provider guests must sign in using the appropriate SSO connection.

One Time Password sign-in methods

Nintex provides two OTP sign-in methods:

  • One Time Password (OTP) connection: An identity provider connection that is configured for the environment and appears as an option on the Login page.

  • Legacy OTP sign-in: A last-resort sign-in method that is available for all environments and portals through a separate URL. It does not appear as an option on the Login page.

Both OTP methods are available only to internal users who:

  • Belong to a verified domain.

  • Have already been added to the environment.

OTP does not automatically add or onboard users to an environment. Guest users and Nintex External Users cannot sign in using either OTP method. Use the One Time Password (OTP) connection only as a temporary sign-in method when the SSO connection is unavailable. OTP sign-in bypasses the customer’s identity provider. As a result, a user who has been disabled in the identity provider might still be able to sign in using OTP if they remain active in the Nintex environment.

How sign-in works

Users see sign-in options based on the active connections assigned to the environment.

  • If one active connection is assigned, users are redirected to that connection.

  • If multiple active connections are assigned, users select a sign-in method.

  • If users are already authenticated with their identity provider, they are signed in without completing the identity provider sign-in flow again.

  • Inactive connections do not appear on the sign-in page, even if they are assigned to an environment.

Default connection

The default connection is automatically assigned to newly provisioned environments. When an organization is created, the username and password option is set as the default. You can set an SSO connection as the new default connection.

Note: Changing the default connection does not update existing environments. To change sign-in options for an existing environment, assign or remove connections from that environment.

Set the default connection

  1. Access the Organization portal. For more information, see Access the Organization portal.

  2. Click Identity provider connections.

  3. Under Active connections, select next to the SSO connection you want to set as the default.

  4. Select Set default.

The selected SSO connection is used as the default connection for newly provisioned environments.

Configure an SSO connection

Use an SSO connection to let users sign in through a SAML-based identity provider.

  1. Access the Organization portal. For more information, see Access the Organization portal.

  2. Click Identity provider connections.

  3. Under Identity provider connections, click Add connection.

  4. Select the Identity provider from the drop-down menu.

  5. Type a Name for the new connection.

    Note: This name is used in the Organization portal to identify the connection.

  6. Type the Login label. This is the name displayed in the login options.

  7. Click Confirm.

After you create the connection, assign it to the environments where users need to sign in.

Note: 
  • Only one Nintex External users connection can be added for an organization. After it is added, it can be activated or deactivated.
  • When the first SSO connection is added the existing username and password connection is permanently converted to the OTP connection. Until the newly added SSO connection is assigned to an environment, users will be able to authenticate using OTP instead of username and password

Assign connections to environments

Assign a connection to an environment to make it available as a sign-in option. Connections can be assigned to one or more environments. Newly added connections are not assigned to any environments by default. For more information, see Environments.

Edit an identity provider connection

Edit a connection to update its name, login label, or SSO metadata.

  1. Access Organization portal. For more information, see Access the Organization portal.

  2. Go to Identity provider connections.

  3. Select next to the connection you want to edit.

  4. Click Edit.

  5. Update the required fields.

  6. Click Save.

Only the changes you make are applied. For example, you can update the login label without updating the SSO metadata.

Activate an identity provider connection

Activate an inactive connection to make it available again.

  1. Access the Organization portal. For more information, see Access the Organization portal.

  2. Click Identity provider connections.

  3. Under Inactive connections, click next to the connection you want to activate.

  4. Select Activate.

If the connection is assigned to an environment, it appears on the sign-in page for that environment.

Deactivate an identity provider connection

Deactivate a connection when users no longer use it to sign in. For example, you can deactivate an SSO connection while you investigate a configuration issue.

When a connection is deactivated:

  • It no longer appears on the sign-in page.

  • Users cannot sign in through the connection.

  • The connection is not deleted.

  • Environment assignments are not changed.

  • The connection can still be edited.

  1. Access the Organization portal. For more information, see Access the Organization portal.

  2. Click Identity provider connections.

  3. Under Active connections, click next to the connection you want to deactivate.

  4. Click Deactivate.

The connection is moved to Inactive connections.

Important: 
  • You cannot deactivate the default connection.

  • You cannot deactivate the last active SSO connection.

  • An inactive connection does not appear on the sign-in page, even if it is assigned to an environment.

  • You can reactivate inactive connections.

Migrate to a new SSO connection

You can migrate to a new SSO connection by creating and validating a new connection before deactivating the previous connection. This lets you test the new connection before it is used by all users.

  1. Create a new SSO connection. For more information, see Configure an SSO connection.

  2. Assign the new connection to a test environment, if available. For more information, see Assign connections to environments.

  3. Confirm that users can sign in with the new connection.

  4. Assign the new connection to each environment that uses the previous connection.

  5. Deactivate the previous connection.

Identity provider connections fields and settings

Section Selection (or column or field) Description
Identity provider connections Connections
  • Active connections: Displays identity provider connections that are active and available to assign to environments.

  • Inactive connections: Displays identity provider connections that are inactive and not available for sign-in.

  • All connections: Displays all identity provider connections configured for the organization, including active and inactive connections.

  Name

The internal name used to identify the connection in the Organization portal. This name appears on the Environments page when the connection is assigned. It is not generally shown to users.

  Login label The label shown for the connection on the sign-in page. If this field is not set, the sign-in button uses the connection name.
  Provider

The identity provider used as the authentication method.

  Status Shows whether the connection is active or inactive.
  Configured by The name of the user who last configured the connection.
  Date configured The date and time when the connection was last configured.
  Options ()

Deactivate: Disables the selected connection.

At least one active SSO connection must remain enabled for the organization to be accessible, excluding external users.

External users configuration Manage access for users outside your organization Shows whether the external users connection is active. Manage this setting by activating or deactivating the Nintex External users connection.