# Admin Login Using an IdP Provider

## What

After an identity provider (IdP) and administrator group access are configured, FileWave Central and FileWave Anywhere show an IdP sign-in option. Administrators can authenticate through Microsoft Entra ID, Okta, Google, or Keycloak instead of using a local FileWave account.

<p class="callout info">**FileWave Central 16.4 uses the computer’s system browser for IdP authentication instead of an embedded sign-in frame.** The change is automatic and requires no additional FileWave setting. FileWave Central 16.3.x and earlier use the embedded flow.</p>

## When/Why

Use IdP administrator login when access should follow the organization’s identity-provider policies, including provider-managed multi-factor authentication, conditional access, saved browser credentials, and SSO session behavior.

Local FileWave administrator accounts remain available through the local-login option. Keep a secured local administrative path for recovery and IdP troubleshooting.

## FileWave Central 16.4

1. Start FileWave Central and select the intended FileWave Server.
2. Select **Login via IdP**.
3. FileWave Central opens the configured default system browser instead of displaying the provider inside Central.
4. Select the provider when more than one IdP is available, then complete the provider’s sign-in, multi-factor authentication, and consent or policy checks.
5. After successful authorization, FileWave Central completes the connection using the permissions assigned to the matching IdP Group Account.

Because the provider runs in the system browser, it can use browser-managed credentials and an existing provider session when the IdP and organization policy permit it. No FileWave preference switches the 16.4 desktop application back to the embedded frame.

## FileWave Anywhere

1. Open FileWave Anywhere in a supported browser.
2. Select the configured provider on the login page.
3. Complete the provider sign-in and return to FileWave Anywhere.

FileWave Anywhere already operates in a browser, so the FileWave Central 16.4 system-browser change does not create a separate Anywhere login model.

## Browser sessions and sign-out

<p class="callout warning">**Signing out of FileWave ends the FileWave session; it does not necessarily end the identity-provider session stored by the browser.** If the system browser still has an active IdP session, the next FileWave login may authenticate automatically. Sign out from the provider or use the intended browser profile when a complete SSO sign-out or account change is required.</p>

- Verify the displayed provider account before approving access, especially on shared administrator workstations.
- Apply browser and device security controls appropriate for privileged administration.
- Test IdP login with a non-emergency administrator before relying on it as the only routine access path.
- Keep IdP group membership and FileWave permissions aligned with least privilege.

## Troubleshooting

<table id="bkmrk-troubleshooting-table"><thead><tr><th>Symptom</th><th>Check</th></tr></thead><tbody><tr><td>**Login via IdP is not available**</td><td>Confirm that an IdP is configured for administrator use and that the required IdP Group Account exists in **Assistants &gt; Manage Administrators**.</td></tr><tr><td>**FileWave Central does not open a browser**</td><td>Confirm that the operating system has a working default browser and can open HTTPS links, then restart Central and retry.</td></tr><tr><td>**The provider signs in, but Central does not complete the connection**</td><td>Review the provider configuration, group membership, FileWave permissions, redirect/authorization result, and FileWave Server logs. Retry without closing the browser before the provider finishes.</td></tr><tr><td>**The wrong provider account is reused automatically**</td><td>Sign out from the IdP in the system browser or switch to the browser profile containing the intended administrator account, then start the FileWave login again.</td></tr><tr><td>**The user authenticates but lacks access**</td><td>Confirm membership in the mapped IdP group and review the permissions assigned to that IdP Group Account in FileWave Central.</td></tr></tbody></table>

## Related Content

- [FileWave Identity Provider (IdP) Integration Overview](https://kb.filewave.com/books/identity-provider-idp-integration/page/filewave-identity-provider-idp-integration-overview)
- [Adding IdP Groups for FileWave Authentication](https://kb.filewave.com/books/identity-provider-idp-integration/page/adding-idp-groups-for-filewave-authentication)
- [IdP Setup: Google](https://kb.filewave.com/books/identity-provider-idp-integration/page/idp-setup-google)
- [IdP Setup: Microsoft Entra ID](https://kb.filewave.com/books/identity-provider-idp-integration/page/idp-setup-microsoft-entra-id-azure)
- [IdP Setup: Okta](https://kb.filewave.com/books/identity-provider-idp-integration/page/idp-setup-okta)
- [IdP Setup: Keycloak](https://kb.filewave.com/books/identity-provider-idp-integration/page/idp-setup-keycloak)