Download Message Segment Specifications
Transcript
Physician Portal evaluates the current user session in conjunction with the SAML assertion provided, and performs authentication to establish a new session under the following conditions (evaluated in the order shown): ❑ ❑ ❑ The partner application link has launched a new browser window. The partner application link attempts to update the existing browser window, for which the Physician Portal session has timed out. A different user has authenticated to the running partner application since the Physician Portal browser window was launched. This requires authentication to Physician Portal as the “new” partner application user. About SSO User Initialization Before successful SSO authentication to Physician Portal can occur, users of trusted partner applications must be mapped to Physician Portal. This process includes verifying that the user knows his/her Physician Portal credentials (User ID and Password) the first time the user accesses Physician Portal via a link from the partner application. The first time the user initiates SSO-based access to Physician Portal, the absence of a user mapping on file for the user elicits a login page, displaying a message indicating why the credentials are being requested. Both new and existing Physician Portal users will see this page on their first SSO-based access attempt. Both temporary passwords (issued by MedPlus Customer Support) and permanent passwords (set by the user via the Change Password function) are accepted on this page. Upon successful authentication of a user’s Physician Portal User ID and Password, a mapping record is stored within Physician Portal that relates the Physician Portal user identity to the partner application user identity passed within the SAML assertion. At the same time, the user’s Physician Portal password is obfuscated, so the user will only be able to access Physician Portal via SSO from that point forward. If the user requires both SSO-based and password-based authentication, MedPlus Customer Support may be contacted to request a password reset. Existing Physician Portal practices are employed for password resets; that is, the user must change the password upon the first password-based login following a password reset. 156 • • • Chapter 6: Physician Portal SSO Specification • • •