1.0 Introduction
This article helps you to access and manage Federated Authentication Identity Provider (IdP) configurations for cloud connections in Fortanix Key Insight.
It also describes:
How to access the Authentication user interface (UI) in Fortanix Key Insight.
How to add a new cloud IdP configuration.
How to manage (edit and delete) the existing cloud IdP configurations.
2.0 Access Authentication UI
You can access the Authentication UI from the Fortanix Key Insight left navigation panel.
For the selected Fortanix Key Insight account, the Authentication page lists all the existing cloud (AWS, Azure, and GCP) IdP configurations.
.png?sv=2022-11-02&spr=https&st=2026-03-22T15%3A09%3A35Z&se=2026-03-22T15%3A21%3A35Z&sr=c&sp=r&sig=9vfeNkiYJq%2BlN1UJGvW6Im%2FKF83kaUihuxAFs3blPH4%3D)
Figure 1: Access Authentication UI
3.0 Add a Federated Authentication IdP Configuration
For cloud connection, you can add a new federated authentication IdP configuration using ADD CONFIGURATION.
For more information, refer to Getting Started with Cloud Connection.
4.0 Manage Federated Authentication IdP Configurations
For each Federated Authentication IdP configuration, you can perform the following:
Edit
Delete
NOTE
Only users with the Account Administrator and Group administrator roles can add, edit, and delete the IdP configurations in Fortanix Key Insight.
Expired IdP configurations will have the Status column marked as Expired. For these configurations, you must click
and click Authorize to perform reauthorization.
For Microsoft Entra ID IdP using the single page application (SPA) option in Azure, you must reauthorize it every 24 hours because refresh tokens are valid only for 24 hours, according to the Microsoft's official documentation.
4.1 Edit the IdP Configuration
You can modify the IdP configuration details if required.
Perform the following steps to edit the IdP configuration:
Select the required IdP configuration to edit.
Click
.On the Edit Configuration – Authorization Code Flow or Edit Configuration – Client Credentials Flow page (depending on the selected authentication method), update the required values.
NOTE
On the Edit Configuration – Client Credentials Flow page, if the API Gateway URL is updated, the Client ID and Client Secret must also be updated to ensure that credentials configured by one account administrator cannot be redirected to a gateway managed by another account administrator.
Click Authorize to apply the changes.
4.2 Delete the IdP Configuration
Use this feature to remove an IdP configuration and its associated information.
Perform the following steps to delete the IdP configuration:
Select the required IdP configuration.
Click
. The deletion confirmation dialog box will appear.Read all the details and enter the cloud connection name.
Click DELETE.
WARNING
Deleting the IdP configuration cannot be undone.
The IdP configuration will be removed from the Authentication page.