Initializing help system before first use

Authenticating Users with Active Directory or LDAP

Xpress Insight authenticates users against credentials stored within the Xpress Insight database by default. It can be configured to authenticate against LDAP—either a standard LDAP directory or Microsoft Active Directory (AD)
Note LDAP integration is not available with a Community license.
Xpress Insight has two levels of authentication:
  • Partial authentication verifies users stored in the Insight database against details retrieved from LDAP.
  • Full integration enables Xpress Insight to synchronize user accounts (verify and create a new user, or update an existing user) within Insight, if that user has the correct LDAP group membership. If the user attempting to log in does not have a valid LDAP account, or does not have the Insight Group qualification in LDAP, they will be denied access.
Xpress Insight accesses AD as a LDAP server, and so the rest of this documentation will use LDAP as a generic term for both LDAP and AD.
Note The LDAP provider must be capable of providing an attribute on the user record which holds the group membership.

© 2001-2020 Fair Isaac Corporation. All rights reserved. This documentation is the property of Fair Isaac Corporation (“FICO”). Receipt or possession of this documentation does not convey rights to disclose, reproduce, make derivative works, use, or allow others to use it except solely for internal evaluation purposes to determine whether to purchase a license to the software described in this documentation, or as otherwise set forth in a written software license agreement between you and FICO (or a FICO affiliate). Use of this documentation and the software described in it must conform strictly to the foregoing permitted uses, and no other use is permitted.