User Directories
A user directory represents an external identity service that users can sign in through, instead of (or in addition to) a Trivore ID username and password. Signing in via a user directory can optionally create a new Trivore ID user account automatically, if a matching one doesn't already exist.
A Trivore ID user account can be linked to accounts in multiple different user directories — even multiple accounts within the same directory. End users can manage these links themselves. Only one link can be primary at a time; some fields (such as first/last name, locale, and username) are only updated from the primary directory when the user signs in through it or it's synchronized. Trivore ID also supports synchronizing a directory to mass-import all of its users.
Configuring a new directory starts from the User Directories view on the Main Menu, via Add directory, which prompts for a directory type. The exact list of available types depends on your deployment, but includes at least:
- Active Directory Domain Services (AD DS)
- Active Directory Federation Services (ADFS)
- Azure AD / Entra ID
- Lightweight Directory Access Protocol (LDAP)
- Microsoft
- MPASSid
- OpenID Connect
- OP Identity Service Broker
- Opinsys
- Security Assertion Markup Language (SAML)
- Smart card
- Suomi.fi
- Telia Identification Service
- Trivore ID (federating from another Trivore ID instance)
- Simple REST API
- Social login providers, such as Google, Facebook, and Apple ID
In this section
| Page | Description |
|---|---|
| Common user directory settings | Settings shared by every directory type: display options, login translations, user attribute mapping, and group import |
| Common SAML user directory settings | Settings shared by all SAML-based directories (ADFS, SAML, Suomi.fi) |
| Login requirements | Restricting sign-in via a directory based on attribute values, such as group membership |
| Advanced features | Linking multiple directories to one account, on-demand account creation via suomi.fi-tunnistus, and redirecting straight to a directory's sign-in |
| ADFS | Configuring Active Directory Federation Services |
| Azure AD / Entra ID | Configuring Azure AD / Entra ID |
| MPASSid | Configuring the Finnish education sector identity service |
| OP | Configuring the OP Identity Service Broker |
| SAML | Configuring a generic SAML 2.0 identity provider |
| Suomi.fi | Configuring the Finnish national strong identification and sign-in service |
| Trivore ID | Federating sign-in from another Trivore ID instance |