Environment Description
Environment Description

Environment Description

The Workcloud Communication solution supports the use of OAuth2 authentication using ADFS to provide the ability for a single device to be used by multiple users. This is often referred to as the Shared Device Model as opposed to the Dedicated Device Model.
The support of a Shared Device model is based on the configuration of a Relying Party Trust in the customer’s ADFS server. A fully integrated Workcloud Communication solution includes integrating with an Identity Provider (IdP) solution, like AD/ADFS. The functionality of an IdP connection serves three purposes:
  1. User Authentication
    • Granting user access to the system by validating credentials
    • Providing a shared device usage model
  2. User Provisioning
    • As associates join and leave the enterprise, they are added to and deleted from the IdP by the customer administrators. The connection to the IdP with Profile Manager and PTT Pro provides the ability to automatically synchronize the user databases with changes made in the IdP.
  3. Attribute Transformations
    • Various elements in the IdP database can be evaluated to determine the profile configuration sent to the users.
When the Workcloud Communication solution is fully integrated with AD/ADFS, all three functions are available. Both Profile Manager and PTT Pro rely on the IdP to simplify and automate what would otherwise be a manual process.
The focus of this document is the ADFS configuration and how this determines the configuration of PTT Pro and Profile Manger.