Avaya Workspaces login uses Security Assertion Markup Language (SAML), if configured in Avaya Breeze® platform Authorization Service.
The Avaya Breeze® platform Authorization Service is used by real-time reporting of stream. If SAML integration is configured in the Avaya Breeze® platform Authorization Service, then:
SAML authorization feature is used without any configuration required on the Avaya Analytics™ real-time stream pods (orca-streams-rest, orca-streams-data-publisher) or Avaya Breeze® Authorization service pods (orca-breeze-authorization-service).
When attempting to access the Avaya Workspaces URL, unauthorized users are redirected to the Avaya Breeze® platform Authorization Service, which further redirects users to your identity provider (IdP), and prompts the user for credentials.
After successful authentication, the Avaya Breeze® platform grants users authorization using an authorization token. If users have the correct permissions set in Avaya Control Manager, they can access Avaya Workspaces.
When the dashboard icon in Avaya Workspaces is selected, this authorization token is passed to the Avaya Analytics™ real-time stream pods, which use the verification features of the Avaya Breeze® platform Authorization Service through orca-breeze-authentication-service to confirm that the user has a supervisor role. The user can see reports using the supervisor role.
For more information about SAML support, see Configuring SAML Authentication section in Administering Avaya Breeze® platform guide and Avaya Workspaces single sign-on in Deploying Avaya Oceana® Solution guide.