Preference Name = SHLDAUTAPP
Full Name - Approvers must be authorized with SSO/Login
The "Approvers must be authorized with SSO/Login" feature increases the security door capability of external routed requests that are sent to resources. When this feature is enabled, external routed requests for approval links can only be accessed by the approver who is an Equus Platform user. The external routed request covers the following:
Before enabling, users should be aware that the identities that are being selected to approve should have a valid method of logging in to the Equus Platform to approve or reject. To enable this feature, access the System Preference screen and set the category to "Security". Set the "Approvers must be authorized with SSO/Login" to Yes and click
.
Setting the preference to Yes activates the Approvers must be authorized with SSO/Login.
Setting the preference to No, activates the Use old Policy Field Exceptions routing method and ignores the Approval Ruleset (System code: EQEXLEGACY)
Note, that the configuration is supported by company override.
If this system preference is enabled, routed approvals will be subject to the following workflow:
The approver is an Equus Platform user and/or with or without an SSO Account.
If logged in, the user will be automatically redirected to the approval information.
If no active session, the user will be redirected to the Equus Platform login page or to SSO login page whichever is applicable.
The same result will still be observed if the approver is not an Equus Platform user but with a valid SSO configuration.
The approver is an unknown Equus Platform user and the client (server instance) does not have a valid SSO Configuration.
The user will be prompted with an error page indicating access is not allowed.
If adding an approver and the email is not recognized as a valid AssignementPro user, a banner will be shown indicating "Non-users are selected for Approval Routing and Approval Authentication is enforced. Verify approvers have a valid SSO authentication or create new user accounts”.
This is also applicable for the Core Flex approval processes.
Things to Note
Before enabling this feature, keep in mind that approvers must have access to the Equus Platform in order to open the link.
The SAML assertion that is being sent to the Equus Platform from the client’s IDP must have an entry for email.
Since the system pref. depends on the configuration of the webconfig, it will not work if your Equus Platform setup uses multiple IDPs.
Note, the System Preferences “Approvers must be authorized with SSO/Login” (System code: SHLDAUTAPP) and “Use old Policy Field Exceptions routing method and ignore Approval Ruleset” (System code: EQEXLEGACY) cannot be enabled at the same time.


