Configuring the Login/Sign-up page
XTM Portal Administrators can configure and customize the XTM Portal Login/Sign-up page.
Warning
Before you disable the Default login by password and the Login with link, ensure that you and/or other XTM Portal Administrators can log in with SSO, which will be the only login method from now on.
Otherwise, you can block yourself access to XTM Portal. If that happens, visit our Support Portal.
Log in to XTM Portal as an Administrator.
In the menu on the left of the screen, select the cog icon
. The Settings tab screen is displayed.
In the Settings tab screen, select the GENERAL tab.
In the General settings tab screen, select the LOGIN/SIGN-UP tab.
In the LOGIN/SIGN-UP tab, make the required settings:
Note
You can check what the Login/Sign-up page will look like, in the Preview section, to the right of the LOGIN/SIGN-UP tab screen.
In the Login section, select the method(s) for logging in to XTM Portal. To do so, use the relevant toggle switches:
Default login by password: this login method is enabled by default. That means, users can log in with their email address and password. For details about this login procedure, see Logging in to XTM Portal using your email and password.
Login with SSO: this login method is disabled by default. if you select it, users can log in with a Single Sign-On (SSO). For details about this login procedure, see Logging in to XTM Portal with a Single Sign-On (SSO). When you select this login method, you must configure at least one SAML client, in the SAML clients section. For details, see step d below.
Login with link: this login method is enabled by default. That means, users can log in with a link that is sent to their email. For details about this login procedure, see Logging in to XTM Portal with a link.
Note
The link with authorized access to XTM Portal is active for one hour. If a user generates a new link before one hour passes, the old link becomes inactive automatically.
Important
You can limit login method for selected users to only SSO. To do so, for the relevant users, set the value of the Is SSO only dropdown to Yes. For details, see Editing user details.
In the User login whitelist section, use Regular Expressions ("regex") to specify email domains from which users can sign up, log in, and use your XTM Portal instance.
Important
This section requires some prior knowledge of Regular Expressions ("regex").
If you need help with configuring regex for your XTM Portal instance, request support:
To request support
Visit our Support Portal.
In the Registration area, select the method that new users should use, to sign up to XTM Portal. To do so, use the relevant toggle switches:
Permit new users to sign up to XTM Portal: specify if new users are able to register using the XTM Portal website. If you turn the toggle switch:
off (default) – new users cannot register via the XTM Portal Login page. They can only be created by an XTM Portal Administrator.
Important
If Login with SSO is enabled in your XTM Portal instance, users will still be able to create their own new accounts if the Create user option has been enabled for their SAML client. For details, see "SAML Settings" section below.
on – new users can register via the XTM Portal Login page. For details, see Signing up to XTM Portal. They can either log in to your instance straight away or not, depending on the Activate user upon registration without XTM Portal Administrator approval setting.
Activate users upon registration without XTM Portal Administrator approval: specify if new users must be approved by an XTM Portal Administrator, or not. If you turn the toggle switch:
Important
This setting only applies to users creating their account via the XTM Portal Login page. Users registering via SSO are active without XTM Portal Administrator's approval. For details, see "SAML Settings" section below.
off (default) – new users must be approved by an XTM Portal Administrator before they can log in to XTM Portal for the first time. An email notifies an XTM Portal Administrator if there is a new user activation request. In the email, the Administrator can select one of two links:
to edit the relevant user: if they select this link, they access the XTM Portal page in which they can edit the new user's details. In that page, they can:
activate the new user to authorize their access to XTM Portal. To do so, they need to switch the Is active toggle on, and select the Save button in the top right-hand corner of the screen.
edit user details that have been entered by the new user (for details, see Editing user details).
An XTM Portal Administrator can also delete the new user, in the XTM Portal user list (for details, see Deleting users).
to log in to XTM Portal: if they select this link, they go to the XTM Portal home page. If they select the users icon
, in the menu on the left of the screen, they can perform a number of actions that affect the new user (for details, see User management).
on – new users are created and activated and can access XTM Portal straight away. An XTM Portal Administrator's approval is not needed.
If you have enabled the Login with SSO toggle switch, in the SAML clients section, configure at least one SAML client. To do so, select the Create button. As a result, the Create SAML client screen is displayed. In it:
In the SAML settings screen, make all required settings:
Name text field (mandatory): the name that you enter here will be displayed in the table at the bottom of the SAML clients section, and on the Log in with "[name]" SSO button, in the Log in page.
Identity provider metadata text field (mandatory): enter XML content or the relevant metadata URI.
Email attribute text field (mandatory if the selected Identity Provider uses a different user name identifier than an email address): enter the SSO attribute that is used for the user email address.
First name attribute text field (mandatory): enter the SSO attribute that is used for the user first name.
Last name attribute text field (mandatory): enter the SSO attribute that is used for the user last name.
Show all attributes mapping toggle switch:
off (default): no additional attributes mapping.
on: the Standard field attributes and Custom field attributes sections are displayed. In them, map the XTM Portal custom fields to your SSO attributes, if required. When you do so, the value for each mapped field is stored in the relevant user's Translation request defaults section (for details, see Creating users). Also, this value is set as default for the relevant custom field whenever the user creates a new translation project. If you also select the Sync on auth toggle switch, the mapped custom field values are updated automatically, if required, when the relevant user logs in with the SSO.
Create user toggle switch:
off (default): automated provisioning is disabled.
on: automated provisioning is enabled.
Sync on auth toggle switch:
off (default): the custom field values are only synchronized with the relevant fields in user's Translation request defaults section when the user is created. However, they are NOT updated at a later stage, if they change.
on: if you have selected the Show all attributes mapping toggle switch and mapped some Custom field attributes, the mapped custom field values are automatically updated at a later stage, when the relevant user logs in with SSO, if they change.
Additional security section settings are optional: enter this data if your SSO settings require this information:
Service provider private key.
Service provider x509 cert.
Service provider rollover x509 cert.
Once you make all the required SAML client settings, select Save in the top right-hand corner of the Create SAML client screen.
Result: each SAML Client that you create is displayed in a separate row in the table at the bottom of the SAML clients section. The table contains these columns:
Name: the name that has been entered for the SAML client.
Create user: shows if automated provisioning has been enabled or not.
Identity provider metadata URI: if metadata URI has been entered.
Service provider keys: if the optional SSO keys have been entered or not.
Service provider rollover cert: if the optional SSO rollover cert has been entered or not.
Metadata URL: a link that points to information about SSO provider.
Select the Save button in the top right-hand corner of the screen.
Result: the relevant Login/Sign-up page settings are saved. In the Preview section, to the right of the LOGIN/SIGN-UP tab screen, you see what your login page will look like.