Access to Intranet software like CentricMinds is typically driven by security repositories, with Active Directory being the most common.
Uniquely CentricMinds provides its own security management environment which can be either integrated with Active Directory, or operate as a standalone environment where the creation and authentication of users is managed within CentricMinds.
Users, Groups and Roles Security Model
CentricMinds supports a Users, Groups and Roles security model. Users are also viewed as resources within CentricMinds and as such can be readily shared and used in the same manner as content. This provides unique and powerful ways of displaying content associated with staff within the Intranet. Users are classified based on their function, namely:
- Site Users (readonly access)
- Authors / Approvers (read & write access)
- Organisational Unit Managers
- Global Administrators
Active Directory Integration
CentricMinds provides two key points of integration with an LDAP compliant data source (e.g. Microsoft Active Directory):
A background tasks that connects to and synchronizes a user’s information from LDAP into CentricMinds.
When an individual user attempts to authenticate to CentricMinds, that authentication can be performed against LDAP.
CentricMinds provides a flexible authentication model, which includes support for the following approaches:
CentricMinds provides ‘out of the box’ support for the internal storage of user accounts and their associated authentication. User information is stored within the CentricMinds database.
CentricMinds provides ‘out of the box’ support for authentication with a LDAP compliant data source (e.g. Microsoft Active Directory). The data source will remain the ‘source of truth’ and all authentication attempts via the CMS will include communication and verification with the data source. Information (included security group and role associations) is synchronized and used by the CMS.
Mixed Mode Authentication
A combination of Traditional and LDAP Authentication; which first tests against an LDAP compliant data source (e.g. Microsoft Active Directory) followed by an authentication attempt against the CMS (in the event that the LDAP authentication fails). This provides the ability to support internal authentication of staff, but also supports authentication of external users (who do not have an LDAP account) as needed. This brings greater flexibility in supporting user authentication across varying target audiences.
CentricMinds also provides the ability to perform authentication against external systems (via HTTPS requests) or external databases (via direct data querying).