After migrating to IAMv2
Depending on your configuration, you will need to complete the following after migrating to IAMv2. For an overview of IAMv2, see Identity and Access Management (IAMv2).
Customers with only local accounts
After migration, local user accounts will be successfully migrated.
-
Please notify your ThoughtSpot users that they will be prompted to enter their username and password after migration.
If MFA is configured, users will be prompted to complete two-factor authentication. If users forget their username that is required for the Forgot Password workflow they will not be able to reset their password. -
To validate local account migration, create a user in ThoughtSpot and validate that user creation is successful.
Customers with SAML and local accounts
After migration, authentication will continue as normal for customers with IAM configured. Complete the following steps to migrate to IAMv2.
| Until you complete these steps, your SAML configuration is read-only, and you will be unable to edit this configuration. |
-
From the drop-down at the top right side of the navigation bar, select the Admin tab.
-
Select Authentication > SAML from the left side navigation pane.
The following displays:
-
Request that your IdP administrator configure the following attributes for ThoughtSpot to the values displayed.
-
Assertion Consumer Service URL (Single Sign On URL on IdP)
-
Audience (EntityId on IdP)
-
-
Click Submit when the configuration on your IdP is complete.
This reloads the service. Your configured SAML URLs will now appear on the page.
-
Optionally, you can add a cluster URL in your SAML application as default relay URL.
With IAMv2, the SAML response must have an email attribute. Ensure the email is being sent via SAML response and the email attribute are mapped correctly in Edit SAML connection > Map attributes.
Changes to expect after migration
You can now map certain Identity Provider (IDP) attributes from the ThoughtSpot Admin Console when configuring OIDC or SAML authentication. These attributes include the username, email, and display name. For more information, see Managing authentication with SAML using IAMv2 and Managing authentication with OIDC using IAMv2. After you configure OIDC or SAML authentication, only Okta interacts with your IDP. Your ThoughtSpot cluster does not directly interact with your IDP.
The users section of the Admin Console now supports account activation monitoring. If a user still needs to activate their account, administrators can see that information in the Users section and re-send their activation email. For more information, see Create, edit, or delete a user using IAMv2.
Local users now create their own password during activation. Administrators do not create the password prior to activation. For more information, see Activate your ThoughtSpot account using IAMv2.
Note that whenever you navigate to the login page for ThoughtSpot, you will temporarily see the following URL: identity.thoughtspot.com. This is an expected part of the IAMv2 login experience.
| After migrating to IAMv2, usage of space and special characters will not be allowed while creating Orgs. This is to keep Org names DNS compliant. This restriction applies to only new Org names and does not impact existing Orgs. |