Skip to main content

User Directories

A user directory represents an external identity service that users can sign in through, instead of (or in addition to) a Trivore ID username and password. Signing in via a user directory can optionally create a new Trivore ID user account automatically, if a matching one doesn't already exist.

A Trivore ID user account can be linked to accounts in multiple different user directories — even multiple accounts within the same directory. End users can manage these links themselves. Only one link can be primary at a time; some fields (such as first/last name, locale, and username) are only updated from the primary directory when the user signs in through it or it's synchronized. Trivore ID also supports synchronizing a directory to mass-import all of its users.

Configuring a new directory starts from the User Directories view on the Main Menu, via Add directory, which prompts for a directory type. The exact list of available types depends on your deployment, but includes at least:

  • Active Directory Domain Services (AD DS)
  • Active Directory Federation Services (ADFS)
  • Azure AD / Entra ID
  • Lightweight Directory Access Protocol (LDAP)
  • Microsoft
  • MPASSid
  • OpenID Connect
  • OP Identity Service Broker
  • Opinsys
  • Security Assertion Markup Language (SAML)
  • Smart card
  • Suomi.fi
  • Telia Identification Service
  • Trivore ID (federating from another Trivore ID instance)
  • Simple REST API
  • Social login providers, such as Google, Facebook, and Apple ID

In this section

PageDescription
Common user directory settingsSettings shared by every directory type: display options, login translations, user attribute mapping, and group import
Common SAML user directory settingsSettings shared by all SAML-based directories (ADFS, SAML, Suomi.fi)
Login requirementsRestricting sign-in via a directory based on attribute values, such as group membership
Advanced featuresLinking multiple directories to one account, on-demand account creation via suomi.fi-tunnistus, and redirecting straight to a directory's sign-in
ADFSConfiguring Active Directory Federation Services
Azure AD / Entra IDConfiguring Azure AD / Entra ID
MPASSidConfiguring the Finnish education sector identity service
OPConfiguring the OP Identity Service Broker
SAMLConfiguring a generic SAML 2.0 identity provider
Suomi.fiConfiguring the Finnish national strong identification and sign-in service
Trivore IDFederating sign-in from another Trivore ID instance