In this article, we'll answer the most frequently asked questions about IDS, the newest version of the identity provider. We'll explain what you can do to prepare for your upgrade and what happens next.
A few things to know about the upgrade:
- We are upgrading customers in groups
- We will contact you when it's your turn to upgrade
- This upgrade does not change any features within the products themselves for your users (the login page will be new but will largely work in the same way as before).
- This upgrade does not change the main links (URLs) used to access your Kallidus products
- After the update, only one person will be set to access the 'Manage users' area of the product. They'll have to grant access to others to let them also access this.
Frequently asked questions
What is an identity provider?
The identity provider controls who can log into your Kallidus products and what features they will see when logged in. We are in the process of upgrading to the latest and most secure version of the identity provider, so you can continue to benefit from the very latest technology and the smoothest login journey for your people.
Not sure which identity provider you're using? Follow these steps to find out which Identity provider you're using.
What will change when we move to IDS?
Multi-factor authentication (MFA) can be configured in your site
Multi-factor authentication streamlines the log-in process for your people and offers extra security.
Self-registration can be configured in your site
When configured, learners can self-register in your Learn LMS without waiting to be added manually by the admin team, or by an automated People data-feed.
The process for manually adding users is different with IDS
You’ll still be able to add one-off Users and multiple Users via a spreadsheet import. Take a look at the below articles for more detail(link to articles)
The process for changing a Users password is different for IDS
You’ll still be able to change a Users password, it will just happen in a different place
IDS is the first step towards getting all new reporting and analytics with Power BI
We’re developing all new reporting and analytics with Power BI, and to get access to the new reports, you’ll first need to move to IDS.
Your Customer Experience Manager will contact you to discuss the move to Power BI. In the meantime, take a look at the Reporting and analytics FAQ, and view the New Knowledgebase area for more detail.
Sites with IDS can have multiple SSO providers
If your population uses more than one SSO provider then you can allow this to be setup. Your users will be routed to a login page where they can choose the right SSO option for them.
I'm a Sapling customer. What does this mean for me?
The even better news is that it provides the platform for us to roll out new and exciting modern authentication features, so keep your eyes open for upcoming news on this!
We don't use SSO. Will we need to change the username/passwords my people use?
If you use more than one Kallidus product, you will only need to use one set of username and passwords to log into the Kallidus products moving forward. Once the upgrade has happened, your people can log in with the password they previously used to log into Learn/Perform/Recruit or that they used for Sapling.
This will be the only password used for logging into all Kallidus products from that point forward. i.e. the same username/password will work for all Kallidus products once the upgrade has happened.
IDS does require stronger, more secure passwords, so any Users with a password that falls below the minimum complexity requirements will prompted to change it for a more secure password. This will happen automatically when they log in with their current password.
Will there be a login page if people exclusively use either SSO or username/password, or if there's a mix of both?
The options are:
- Username/Password only: If all users exclusively use username and password for login, the login page will automatically display the username and password fields
- SSO only: If all users login exclusively with SSO, the option to log in with username and password can be disabled
- Mixed login methods: If some users log in with Single Sign-On (SSO) and others use a username and password, the login page can be configured to appear, allowing users to choose their preferred login method
SSO only information. Follow these steps to force the login page to appear (if otherwise, it might be hidden):
- Select the ‘Manage users’ tab (this is only visible post-upgrade)
- Go to ‘settings’
- Switch on the first toggle 'Allow log in using email/username and password'.
Will this upgrade change the products in any way?
Your learners are unlikely to notice any change. If learners login with a username and password (rather than SSO) then they will still go to a login page. This page will look slightly different but will still allow them to login as usual.
From an admin perspective, the large chunks of admin will be the same. However, you will see a new area entitled 'Manage users'. This will allow you to add Users (if needed) and change passwords if somebody has forgotten theirs.
If you manually import Users into Learn then you will also experience a change in the way this occurs. This does not impact your 'feed' into Learn but our manual import has been improved. You can find out more about this here.
What happens to the record of User sign-ins?
When your site moves to IDS, records of previous sign-ins will no longer be available. If you would like to keep a record of sign in activity prior to upgrading to IDS, we recommend exporting the data in the 'Monthly statistics report' to an Excel spreadsheet for future reference.
What is the timeline for my upgrade? Will my site still be available?
We will contact you with the information about your upgrade timeline. If you are unsure, please speak to your Customer Experience Manager (CEM) in the first instance. Your site will be unavailable for around 5 minutes from the start of your upgrade time. We'll outline this in our communications with you.
How is my new SSO configuration set it up Can we self serve the upgrade?
There are two options here:
1. Use our self service upgrade page. This gives you control over your upgrade and when it occurs. We are contacting customers in groups to make this self service upgrade page available. We recommend getting your IT team involved from the start of the process.
2. Having a meeting with Kallidus about your upgrade. Please discuss this with your Customer Experience Manager (CEM) if you would like for this to happen.
How do I give access to others to manage users?
As part of your upgrade, you will start to use the new Manage users area. This area allows users to see all people within your system. They will see all records. These records include names, usernames and email addresses.
Once you have upgraded, you can give people access to the Manage Users tab. Only the person we contacted about your upgrade will have initial access.
What do I need to tell my Users?
The upgrade only takes a few minutes to move over. Your site will 'blip' to downtime for a few minutes before being fully available again. We will arrange this to be at a quiet part of the day. As such, we do not recommend you advise your users on this occasion.
Important: If your Users use a '/external' link, this will continue to work post-upgrade.
My Users are logging in via username/password. What happens if they use the wrong details?
- We allow 5 incorrect username/password attempts
- On the sixth incorrect attempt, the User will be locked out for 5 minutes
- After 5 minutes the User can try again
- No administrator intervention is required
What types of SSO do you support?
We will support all the Single Sign-on (SSO) types we currently support. So, if your SSO currently works then you can expect this to be compatible post upgrade. In addition, we can now support any SSO product which is underpinned by one of these protocols:
- SAML 2
- OIDC
- WS-Federation
Do you support IP-initiated Single Sign-on?
Yes.
We have 'questions and answers' switched on for password recovery. Will this remain?
We are moving to a more standard and secure password recovery where you enter your email address to recover your password. Questions and answers will no longer be part of this process.
Have a question we haven't covered?
If you have further questions then please either raise a ticket with our support desk or get in touch with your Customer Experience Manager.
Get deeper learning in The Academy
The Academy is your learning hub for Kallidus products, including live events, eLearning videos, and more. If you're new to The Academy or know someone who is missing out on free learning, contact your Customer Experience Manager or the Support Team to sign up today.
Discover the latest insights, tips and industry news on the Kallidus blog.