| Where Can I Use This? | What Do I Need? |
|
| The Cloud Identity Engine service is free; however, the
enforcement points utilizing directory data may require specific
licenses. Click here for more
information. |
After configuring your specific authentication sources—such as a SAML 2.0 Identity
Provider, OpenID Connect (OIDC), or Client Certificates—you must
create an Authentication Profile to define how these methods are applied to
your users. This profile functions as the policy layer of your identity
infrastructure, allowing you to specify exactly which verification method is used
for different segments of your organization. You can specify one or more
authentication types by group or by directory or for all directories.
To use more than one authentication type in your authentication profile, you must
configure a directory in
the Cloud Identity Engine. For a single client certificate authentication type,
configuring a directory in the Cloud Identity Engine is optional. There is no
directory requirement for a single SAML 2.0-compliant authentication type.