-
Identity Tile (version 25)
Total Users – total number of internal Canary users created within the Identity service Active Users – total number of Canary users who are currently logged in to a Canary application (Canary Admin,…
-
Identity Tile (version 25)
Total Users – total number of internal Canary users created within the Identity service Active Users – total number of Canary users who are currently logged in to a Canary application (Canary Admin,…
-
Canary Admin Timeout
Hello, I have observed that Canary Admin logs you off after "some period" (unable to determine it). Is there a setting that can be configured to logoff Canary Admin users (e.g.…
- Answered
-
Easy enable/disable user in Canary System
Hello, It would be really great to have an easy enable/disable user access, disabling entirely the user from anything that can be done in the system. As of today,…
-
Add metadata to users or groups in Identity service
Hello, A nice feature that I wasn't able to find is to add metadata properties to users and groups (or have an extra couple of fields to fill by default).…
-
Prevent a user to create charts/applications
Hello, Is there a way to prevent a user to create Axiom reports? I can see there are options to deny access to views (but prevents the user to open reports on views denied) and deny access to Read…
-
Enable/Disable Users
Hello I am unable to find in documentation or Canary system anything that allows Canary administrators to enable/disable users (by users I refer to Axiom users) - but I may be wrong here!…
-
Allow for ACL's on functionality/tiles to support segregation of duties
Hello, I think it would be very valuable to define ACL's at a level that are more related to the activities that different users may have. Axiom contains more granular functionality,…
-
How to Add an OpenID Connect Identity Provider (version 25)
By default, Canary uses Windows AD for user authentication; however, Canary also supports OAuth 2.0/OpenID Connect. This gives end users alternate options for signing into Canary's application tools…
-
Identity Provider Routing (version 25)
Identity Provider Routing is used to control which identity providers (e.g. Active Directory, Anonymous, OpenId Connect provider, etc.) are available to end-users logging in based upon their IP…
-
How to Add an OpenID Connect Identity Provider (version 24)
By default, Canary uses Windows AD for user authentication; however, starting in v24, Canary also supports OAuth 2.0/OpenID Connect. This gives end users alternate options for signing into Canary's…
-
Mapping Windows External Groups to Canary Group v24
We've installed a new v24 Canary server and I'd like to know if there is a way to map our existing Windows Groups to Canary Groups in Identity ahead of time? I was able to map one that I belong to,…
- Answered
-
How to Change the Identity REST API Port (version 25)
By default, the Identity service is set to listen on 55353 for inbound client applications (e.g. Axiom, Excel Add-in, and Admin) trying to authenticate.…
-
How to Change the Identity REST API Port (version 24)
By default, the Identity service is set to listen on 55353 for inbound client applications (e.g. Axiom, Excel Add-in, and Admin) trying to authenticate.…
-
Connecting v23 and v24 historians via Remote Historian View
We currently have two Canary servers, one v23 and one v24. Is it supported to set up Remote Historian Views on each server so that the Axiom instance on each can access the Views from the other? Or,…
- Answered
-
Auth Flow to Use Custom URI Fully
Right now, you can set up a custom URI/URL for Canary by creating a DNS record that points to the Axiom machine and adding that URL to the Identity Tile redirect list.…
-
Kerberos Authentication Limitation (version 24)
Kerberos does not work when connecting to Identity from the local server using a FQDN When a client on the Identity server connects to Identity using a FQDN and attempts to authenticate with Kerberos,…
-
Kerberos Authentication Limitation (version 25)
Kerberos does not work when connecting to Identity from the local server using a FQDN When a client on the Identity server connects to Identity using a FQDN and attempts to authenticate with Kerberos,…
-
Cache Credentials
I don't know if that's exactly the right term. But with Kerberos of OpenID authentication, laptops and machines usually have the ability to cache credentials.…
-
How to Configure Kerberos Authentication in Edge, Chrome, and Firefox (version 24)
If wishing to enable Kerberos within the Identity service, the following configuration changes may be needed depending on the browser you are using. Edge Install the Edge administrative template .…
-
How to Configure Kerberos Authentication in Edge, Chrome, and Firefox (version 25)
If wishing to enable Kerberos within the Identity service, the following configuration changes may be needed depending on the browser you are using. Edge Install the Edge administrative template .…
-
Identity Tile (version 24)
Total Users – total number of “Canary” users created within the Identity service Active Users – total number of Canary users who are currently logged in to a Canary application (Canary Admin, Axiom,…
-
Identity Architectures (version 24)
When installing the Canary system, it is important to determine where the Identity service will be located as other Canary services must connect to it when authenticating and authorizing users.…
-
Identity Architectures (version 25)
When installing the Canary system, it is important to determine where the Identity service will be located as other Canary services must connect to it when authenticating and authorizing users.…
-
How to Configure a Remote Collector when Tag Security is Enabled (version 25)
If Tag Security is enabled within the Identity service, a remote Collector will not be able to write to the Historian by default. The SaF service on the Collector server must be configured to use an…