Integrations

/

Akamai Identity Cloud SAML2 SSO with Flexopus

Manage access to Flexopus centrally via Akamai Identity Cloud – securely, easily, and without manual user maintenance.

No items found.
No items found.

What is the Akamai Identity Cloud SAML2 SSO integration?

The Akamai Identity Cloud SAML2 SSO integration connects Flexopus to Akamai via the SAML2 protocol (Security Assertion Markup Language). In this process, Akamai takes on the role of the Identity Provider (IdP): Users authenticate themselves with their existing company login credentials to Akamai and thus automatically gain access to Flexopus – without a separate password.

Upon the first successful login, the user profile is automatically created in Flexopus. In addition to the basic login, optional attributes such as department or job title can be transferred from Akamai to Flexopus.

What is the purpose of integration?

The integration ensures that employees can log in to Flexopus with a single login – their usual company data. This saves time, reduces password problems and increases security.

Typical use cases include:

  • Central access management: Administrators define in Akamai which users or groups are granted access to Flexopus. Changes take effect immediately.
  • Automatic user setup: New employees are automatically registered in Flexopus upon their first SSO login – without any manual effort for administrators.
  • No separate password: Employees use their existing Akamai login credentials and do not need to remember an additional password.

How easy is the setup?

Setting up the Akamai SAML2 SSO integration can be done in just a few steps. Essentially, a new SAML2 application for Flexopus is created in Akamai, the necessary parameters (Entity ID, ACS URL) are taken from the Flexopus settings, and then the metadata file is uploaded from Akamai to Flexopus.

For complete step-by-step setup instructions, please visit our Help Center.

What are the advantages of integration?

  • Single Sign-On: Employees log in with their existing company login details – no additional password is required.
  • Automatic user registration: New users are automatically created in Flexopus upon their first login, without manual data maintenance.
  • Centralized access management: Access is controlled directly in Akamai – including group and user management.
  • Increased security: The SAML2 protocol ensures secure authentication. Optional deactivation of email/password login is possible.
  • Minimal data exchange: Only the necessary user attributes are transferred (name, email, UPN). Optional fields such as department or job title can also be synchronized.
  • Included free of charge: Integration is included in the Flexopus subscription (depending on the chosen plan) – at no extra cost.
Categories
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

Are user profiles created automatically?

Yes. After the first successful SAML2 SSO login, the user profile is automatically created in Flexopus. No manual setup is required beforehand. This default setting is recommended and should only be deactivated in exceptional cases.

What happens when a user is deleted or deactivated in Akamai?

If a user is deactivated or removed from the application in Akamai, they can no longer log in to Flexopus. However, the user profile in Flexopus remains and must be deactivated or deleted separately there if necessary.

Can I change a user's UPN (Unique Principal Name) afterwards?

The UPN is a unique identifier and should not be changed. A change can result in a duplicate user profile being created in Flexopus. If a change is absolutely necessary, please contact Flexopus support at support@flexopus.com.

Are profile pictures from Akamai synchronized?

No. The SAML2 protocol does not support the transmission of profile pictures. Profile pictures must be uploaded directly to Flexopus.

Does Flexopus support IdP-initiated login?

Yes, with a workaround. By configuring the parameter “initiate-sp-login” for the RelayState, the IdP-initiated login is converted into a secure SP-initiated login. This prevents potential security vulnerabilities (e.g. Man-in-the-Middle attacks) and still allows direct login from the Akamai dashboard.