User access to the IdentityIQ application is controlled through an authentication process in which the user's sign-on credentials are validated against an authentication source. The IdentityIQ web application can be configured by the system administrator to perform this authentication in one of three ways:
1. Internal IdentityIQ authentication (default)
2. Pass-Through Authentication (PTA) Configuration
3. Single Sign-On (SSO) Configuration
By default, IdentityIQ authenticates users against its internal user Identity records. However, pass-through authentication and single sign-on can be enabled and configured through the IdentityIQ user interface. In fact, IdentityIQ is not limited to using just one authentication mechanism at a time; multiple authentication methods can be used together.
For more information, see attached white paper.