324
Views
7
Comments
Solved
Architecture Dashboard / AI Mentor Studio - Revoke Access

Hi,

Does anyone know where I see the list of people that have access to our AI Mentor Studio environment and how I can revoke access for one or more persons that have access?

Greetings,

Vincent

2021-08-12 11-00-27
Nordin Ahdi
 
MVP
Solution

Hi Vincent,

All (active) LifeTime users automatically have access to AI Mentor Studio. So if you want to revoke access to AI Mentor Studio, it means you have to deactivate the LifeTime user.

Regards,

Nordin

2020-09-21 08-42-47
Vincent Koning

I wonder if that is the case. Why?

1. Authentication to Lifetime is via oAuth2.0 (the new IT Users authentication method). 

2. Authentication to AI Mentor Studio is done via the OutSystems Community User.

There is no correlation between our oAuth 2.0 user that we defined in our iDP and the OutSystem Community User. So revoking access in Lifetime does nothing for the accessing AI Mentor Studio.

Or is there? It is a long time ago that I setup the IT User authentication part. Not sure if people needed to create a community account with the same UPN as the one in our iDP.

2021-08-12 11-00-27
Nordin Ahdi
 
MVP

There should be a mapping between your community account and your Lifetime user (IT user). During the initial registration in AI Mentor Studio you have to associate your IT user account.

Not sure how it works with the new OIDC authentication in Lifetime. I believe it still requires an active Lifetime user. During login in Lifetime using your external IdP the platform extracts the user info the identity token and matches it against the existing Lifetime user.

So I believe the linking pin for both is the Lifetime (IT) user:

External IdP user ------> Lifetime user <------- Community user (AI Mentor Studio)

2020-09-21 08-42-47
Vincent Koning


I can also imagine a lot and this is also something that I has thought about but I need to be sure. I have created a support ticket for clarification. I'll update here when I get the answer.

2021-08-12 11-00-27
Nordin Ahdi
 
MVP

Sure, I also asked OutSystems to join the discussion.

2021-08-12 11-00-27
Nordin Ahdi
 
MVP

Hi Vincent,

It seems my thoughts were correct.

I received confirmation from OutSystems that deactivating the LT user, will also block access to AI Mentor Studio (even though it uses the community account for login).

The same applies to the new OIDC authentication for SS, SC, LT, builders etc. As long as the LT user is inactive, you won't be able to login to these applications (even though the IdP login is successful).

Hope this helps.

Regards,

Nordin

2020-09-21 08-42-47
Vincent Koning

I have finally been able to test this myself since I was skeptical. But I must say, it works. It does take some time though. The removal of disablement of the user seems to be effectuated during the sync. Thanks for all the responses!

Community GuidelinesBe kind and respectful, give credit to the original source of content, and search for duplicates before posting.