Skip to main content
Nintex Community Menu Bar
Question

Force users to login via AAD

  • December 20, 2022
  • 5 replies
  • 127 views

Forum|alt.badge.img+7

Hi 

How can I force users to login to via AAD not windows sts. I have enabled AAD login on realm but it seems to pick up windows authentication when users browse to the k2 site.

 

Can someone please assist?

 

thanks.

5 replies

Forum|alt.badge.img+7
  • Scholar
  • December 20, 2022

I usually leave only "K2 Trust for Azure AD" in Linked Issuers in K2 Management -> Authentication -> Claims if I only want AAD authentication.

When there's more than one, it asks the user in some such form on access what authentication they want to go there, then it's cached for a while.

Just be careful, if you are accessing K2 Management as an AD user, you may lose access to K2 Management, so it's important to at least add one AAD login to Workflow Server -> Server Rights with Administrator rights before making the change in Realms.


Forum|alt.badge.img+7
  • Author
  • Scholar
  • December 22, 2022

hi @PavelS 

How about assigning task using Name field, which is email address in our case on UMuser with AAD label.  this seems to direct task to AD identity…

Are you able to assist?

 


Forum|alt.badge.img+7
  • Scholar
  • December 22, 2022

hi @PavelS 

How about assigning task using Name field, which is email address in our case on UMuser with AAD label.  this seems to direct task to AD identity…

Are you able to assist?

 

:-) Nintex Support can assist you. I'm just an occasional contributor to the community forum. Try prefixing the email with "AAD:" or what I sent in your second question.


Deon
Forum|alt.badge.img+10
  • Rookie
  • December 22, 2022

Hi,

 

//deleted//

 

Regards

 

d


Forum|alt.badge.img+8
  • Nintex Employee
  • December 30, 2022

Hi @PavelS 

To assign tasks to users on the AAD label, you could use the UMUser Get Users method and pass in the Email address and Label Name as ‘AAD’. See the following KB article with the steps on how to configure a non-default label as a destination user in the workflow: