Comprehensive data protection for all workloads
Post Reply
efd121
Enthusiast
Posts: 73
Liked: 6 times
Joined: Aug 07, 2015 8:45 pm
Full Name: David Engler
Contact:

Enterprise Manager - modify login page

Post by efd121 »

We've updated EM to use SSO and its working as expected but I'm looking for a way to remove the standard login from the webpage so we can force Single Sign-On.
Our SSO requires MFA.
Can anyone point me in the right direction to remove that section of the page?
Dave
Mildur
Product Manager
Posts: 10978
Liked: 3015 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Enterprise Manager - modify login page

Post by Mildur »

Hello David

I checked with the team and unfortunately we cannot hide the standard login form.
If you enable SAML configuration in EM, users can log in to the vSphere Self-Service Backup Portal with SSO accounts only.

Best,
Fabian
Product Management Analyst @ Veeam Software
pirx
Veteran
Posts: 650
Liked: 98 times
Joined: Dec 20, 2015 6:24 pm
Contact:

[MERGED] Enterprise Manager only allow SSO/SAML

Post by pirx »

I've enabled SAML, get redirected to our companies portal and I'm able to login with domain account and MFA. But the old way without SSO and MFA still works, is there any way to disable this - at least for AD users? I already looked in Web.config but if I disable useWindowsAuth login does not work after authentication in Azure AD.


Image
HannesK
Product Manager
Posts: 15596
Liked: 3442 times
Joined: Sep 01, 2014 11:46 am
Full Name: Hannes Kasparick
Location: Austria
Contact:

Re: Enterprise Manager - modify login page

Post by HannesK »

Hello,
I added your request +1 to the existing feature request.

Best regards,
Hannes
pirx
Veteran
Posts: 650
Liked: 98 times
Joined: Dec 20, 2015 6:24 pm
Contact:

Re: Enterprise Manager - modify login page

Post by pirx »

oh, what a bummer. That's the end for BEM here.
alavik
Service Provider
Posts: 2
Liked: 2 times
Joined: Dec 21, 2022 6:34 am
Full Name: Anders Alavik
Contact:

Re: Enterprise Manager - modify login page

Post by alavik » 1 person likes this post

Hello,

This is quite concerning. The purpose of using MFA is undermined if the default account remains accessible, and it's impossible to disable or remove it. We are forced to maintain a local Portal Admin account, which significantly weakens our security posture.
Anders Alavik
Technical Lead, Virtualization infrastructure

InfraCom Managed Services AB
Gamlestadsvägen 1, 415 02 Göteborg
+46 (0) 73 830 54 35
anders.alavik@infracom.se | InfraCom.se
Post Reply

Who is online

Users browsing this forum: Amazon [Bot], Bing [Bot] and 86 guests