User accounts and authentication in Hololight Hub

Objectives

  • Understand the different ways you can create user accounts to use with Hololight Hub.

  • Use single sign-on with accounts using email addresses linked to Microsoft accounts.

  • Understand how to import accounts from a directory server that uses LDAP.

User accounts and authentication in Hololight Hub

Depending on your Hololight Hub deployment, whether it is in the cloud or on an on-premises server, there are different ways your organization can create a pool of user accounts.

Create and verify user accounts in Hololight Hub

Hololight Hub allows you to create new users using Hololight Hub on your web browser. When you create a user, an email is sent to the email address you entered when creating the account. This email lets the user verify the account and create a password. Once verified the user can sign in and start using their account.

Allow user to sign in to Hololight Hub with their Microsoft account and single sign-on

Hololight Hub also supports single sign-on (SSO) if their Hololight Hub account is using an email address tied to a Microsoft account. This means once you create the user, they are able to sign in once using their Microsoft account and then use that account with Hololight Hub.

For Hololight Hub users to be able to use SSO to sign in, Hololight Hub administrators need to first create the users using the Hololight Hub portal. Once the new account is created, as long as a user’s Hololight Hub account’s email address is the same as the email address tied to their Microsoft account, that user can automatically start using SSO. When creating a Hololight Hub user, you can also restrict whether the user can use their email address and password to sign in as well or whether they are required to use SSO as their only Hololight Hub sign in option.

User accounts and authentication in Hololight Hub On-Premises

Since Hololight Hub deployments are often not connected to the internet, authentication with this kind of deployment needs to be done using Hololight Hub’s own authentication server.

Use Hololight Hub-created user accounts

Hololight Hub allows you to create users specifically for Hololight Hub using Hololight Hub through the web browser. As an administrator you just need to create a new user account. You will then assign the new account a password that the user will change their first time signing in.

Import user accounts from an LDAP-supported directory server

Your organization may already have a directory server that uses the Lightweight Directory Access Protocol (LDAP) with users that you want to bring into Hololight Hub. When installing your Hololight Hub deployment, you will have the option to configure a connection to your previously established directory service. After that, all users you add using the Hololight Hub portal are checked against your directory service, giving those users access to Hololight Hub using the same usernames and passwords as they use with their other resources connected to the service.