The SAML 2.0 integration enables ANOW! Automate to function as a Service Provider (SP), delegating user authentication to an external Identity Provider (IdP) such as Microsoft Entra ID, Okta, or Ping Identity. This federated approach ensures that ANOW! Automate access adheres to corporate identity standards and leverages existing identity governance processes, so when a user attempts to log in, ANOW! Automate redirects them to the configured IdP for authentication. After successful verification, the IdP sends a signed SAML assertion back to ANOW! Automate, which then establishes a user session.
ANOW! Automate uses the SAML assertion solely to authenticate and identify the user, typically via their email address. It does not derive application roles or permissions directly from SAML attributes. Authorization within ANOW! Automate is managed independently; user roles and permissions must be configured locally within the platform or resolved through LDAP group membership, depending on the specific deployment architecture. This separation ensures granular control over access within the automation environment.
This integration is designed for large enterprises in financial services, manufacturing, and retail that manage complex, hybrid IT landscapes and require robust, compliant identity management solutions. It helps IT operations and security teams centralize identity lifecycle management, enforce corporate authentication policies, and provide comprehensive auditability across critical IT infrastructure, including workload automation.