Support for SSO/AAD-SAML Authentication in the Decipher VBO Product and Version Blue Prism Enterprise Decipher IDP 2.4 Decipher VBO 1.1 Description: Customer is currently migrating from Decipher 1.2 to Decipher IDP 2.4. The Decipher web application is configured to use Single Sign-On based on AAD/SAML. Users can successfully authenticate to the Decipher web interface via SSO. However, authentication fails when configuring a connection through the Decipher VBO in Blue Prism Enterprise. The Decipher server is reachable through the configured hostname or IP address and port. Invalid usernames are correctly rejected, and the valid user account is recognized. However, authentication fails with an “Invalid Password” or similar authentication error when the Windows credentials of the SSO user are used. The same user can successfully log in to the Decipher web interface via SSO. Current Behavior: A connection to the Decipher server can be established. The configured server and port are reachable. Invalid usernames are rejected with an appropriate error message. The valid user account is recognized. Authentication through the Decipher VBO fails with a password or authentication error. The same user can successfully authenticate to the Decipher web interface via SSO. Expected Behavior: The Decipher VBO should support authentication against Decipher environments configured for AAD-/SAML-based SSO. If SSO authentication is not supported by the Decipher VBO, Blue Prism should provide clear, documented, and security-compliant guidance on the officially supported integration approach. This guidance should specify: which authentication method is supported by the Decipher VBO, which credentials must be provided in the VBO, whether a dedicated non-federated service account is required, whether any additional configuration is necessary, which limitations apply to Decipher IDP 2.4. Business and Security Benefits: Support for SSO/AAD-based authentication in the Decipher VBO is a specific customer requirement but for sure relevant for other Enterprise Customers.. This requirement is primarily driven by security and compliance obligations, as well as the strategic preference to manage access exclusively through centrally controlled Single Sign-On wherever possible. The current dependency on native Decipher credentials or separate non-federated service accounts represents a limitation in SSO-centric environments. This limitation must currently be explained and justified to internal stakeholders from both a security and compliance perspective. Native SSO support in the Decipher VBO, or alternatively a clearly documented and officially supported workaround, would: support compliance with security and regulatory requirements, reduce the number of separately managed credentials, lower administrative overhead, simplify the integration of Blue Prism and Decipher in AAD-/SAML-based environments, improve the suitability of Decipher for organizations with mandatory SSO policies.
... View more