[{"data":1,"prerenderedAt":735},["ShallowReactive",2],{"navigation_docs_en":3,"-en-admin-identityprovider":180,"-en-admin-identityprovider-surround":730},[4,21,37,68,101,137],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":20},"Authentication","i-heroicons-lock-closed","\u002Fen\u002Fauthentication","en\u002F0.Authentication",[10,15],{"title":11,"path":12,"stem":13,"icon":14},"Login","\u002Fen\u002Fauthentication\u002Flogin","en\u002F0.Authentication\u002F1.Login","mdi-login",{"title":16,"path":17,"stem":18,"icon":19},"My profile","\u002Fen\u002Fauthentication\u002Fmyprofile","en\u002F0.Authentication\u002F2.MyProfile","mdi-account-circle",false,{"title":22,"icon":23,"path":24,"stem":25,"children":26,"page":20},"Realtime","mdi-clock-fast","\u002Fen\u002Frealtime","en\u002F1.realtime",[27,32],{"title":28,"path":29,"stem":30,"icon":31},"Asset Overview","\u002Fen\u002Frealtime\u002Fassetoverview","en\u002F1.realtime\u002F1.AssetOverview","mdi-monitor-dashboard",{"title":33,"path":34,"stem":35,"icon":36},"Alarms","\u002Fen\u002Frealtime\u002Falarms","en\u002F1.realtime\u002F2.Alarms","mdi-bell-alert",{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":20},"Analysis","mdi-chart-bar","\u002Fen\u002Fanalysis","en\u002F2.analysis",[43,48,53,58,63],{"title":44,"path":45,"stem":46,"icon":47},"Trend","\u002Fen\u002Fanalysis\u002Ftrend","en\u002F2.analysis\u002F1.Trend","mdi-chart-line",{"title":49,"path":50,"stem":51,"icon":52},"Events","\u002Fen\u002Fanalysis\u002Fevents","en\u002F2.analysis\u002F2.Events","mdi-event-note",{"title":54,"path":55,"stem":56,"icon":57},"Wind analysis","\u002Fen\u002Fanalysis\u002Fwindanalysis","en\u002F2.analysis\u002F3.WindAnalysis","mdi-windsock",{"title":59,"path":60,"stem":61,"icon":62},"Data completeness","\u002Fen\u002Fanalysis\u002Fdatacompleteness","en\u002F2.analysis\u002F4.DataCompleteness","mdi-chart-timeline-variant",{"title":64,"path":65,"stem":66,"icon":67},"Downtime manager","\u002Fen\u002Fanalysis\u002Fdowntimemanager","en\u002F2.analysis\u002F5.DowntimeManager","mdi-progress-alert",{"title":69,"icon":70,"path":71,"stem":72,"children":73,"page":20},"KPI","mdi-speedometer","\u002Fen\u002Fkpi","en\u002F3.kpi",[74,79,84,96],{"title":75,"path":76,"stem":77,"icon":78},"Energy Production","\u002Fen\u002Fkpi\u002Fenergyproduction","en\u002F3.kpi\u002F1.EnergyProduction","mdi-meter-electric-outline",{"title":80,"path":81,"stem":82,"icon":83},"Equivalent Hours","\u002Fen\u002Fkpi\u002Fequivalenthours","en\u002F3.kpi\u002F2.EquivalentHours","mdi-timer-sand",{"title":85,"path":86,"stem":87,"children":88,"icon":90},"Performance Ratio","\u002Fen\u002Fkpi\u002Fperformanceratio","en\u002F3.kpi\u002F3.PerformanceRatio\u002Findex",[89,91],{"title":85,"path":86,"stem":87,"icon":90},"mdi-weather-sunny",{"title":92,"path":93,"stem":94,"icon":95},"PR targets","\u002Fen\u002Fkpi\u002Fperformanceratio\u002Ftargets","en\u002F3.kpi\u002F3.PerformanceRatio\u002F1.targets","mdi-target",{"title":97,"path":98,"stem":99,"icon":100},"Under\u002FOver Performance","\u002Fen\u002Fkpi\u002Funderoverperformance","en\u002F3.kpi\u002F4.UnderOverPerformance","mdi-gauge",{"title":102,"icon":103,"path":104,"stem":105,"children":106,"page":20},"Admin","mdi-gear","\u002Fen\u002Fadmin","en\u002F4.admin",[107,112,117,122,127,132],{"title":108,"path":109,"stem":110,"icon":111},"Roles and Zones","\u002Fen\u002Fadmin\u002Frolesandzones","en\u002F4.admin\u002F1.rolesAndZones","mdi-shield-account",{"title":113,"path":114,"stem":115,"icon":116},"Users","\u002Fen\u002Fadmin\u002Fusers","en\u002F4.admin\u002F2.users","mdi-account-multiple",{"title":118,"path":119,"stem":120,"icon":121},"Activity Log","\u002Fen\u002Fadmin\u002Flogs","en\u002F4.admin\u002F3.logs","mdi-history",{"title":123,"path":124,"stem":125,"icon":126},"Identity providers","\u002Fen\u002Fadmin\u002Fidentityprovider","en\u002F4.admin\u002F4.identityProvider","mdi-fingerprint",{"title":128,"path":129,"stem":130,"icon":131},"Dashboard","\u002Fen\u002Fadmin\u002Fdashboard","en\u002F4.admin\u002F5.dashboard","mdi-view-dashboard",{"title":133,"path":134,"stem":135,"icon":136},"License","\u002Fen\u002Fadmin\u002Flicense","en\u002F4.admin\u002F6.license","mdi-certificate-outline",{"title":138,"icon":139,"path":140,"stem":141,"children":142,"page":20},"Configurator","mdi-wrench","\u002Fen\u002Fconfigurator","en\u002F5.configurator",[143,148,153,165,170,175],{"title":144,"path":145,"stem":146,"icon":147},"Data Acquisition","\u002Fen\u002Fconfigurator\u002Finstances","en\u002F5.configurator\u002F1.instances","mdi-database",{"title":149,"path":150,"stem":151,"icon":152},"System Operators","\u002Fen\u002Fconfigurator\u002Fsystemoperators","en\u002F5.configurator\u002F2.systemOperators","mdi:account-cog",{"title":154,"path":155,"stem":156,"children":157,"icon":159},"Models","\u002Fen\u002Fconfigurator\u002Fmodels","en\u002F5.configurator\u002F3.models\u002Findex",[158,160],{"title":154,"path":155,"stem":156,"icon":159},"mdi-notebook",{"title":161,"path":162,"stem":163,"icon":164},"Model detail","\u002Fen\u002Fconfigurator\u002Fmodels\u002Fdetail","en\u002F5.configurator\u002F3.models\u002F1.detail","mdi-notebook-outline",{"title":166,"path":167,"stem":168,"icon":169},"Wizard Plants","\u002Fen\u002Fconfigurator\u002Fwizardplants","en\u002F5.configurator\u002F4.wizardPlants","mdi-file-tree",{"title":171,"path":172,"stem":173,"icon":174},"Synoptics","\u002Fen\u002Fconfigurator\u002Fsynoptics","en\u002F5.configurator\u002F5.synoptics","mdi-image-multiple",{"title":176,"path":177,"stem":178,"icon":179},"System Checks","\u002Fen\u002Fconfigurator\u002Fsystemchecks","en\u002F5.configurator\u002F6.systemChecks","mdi:shield-check",{"id":181,"title":123,"body":182,"description":723,"extension":724,"links":725,"meta":726,"navigation":727,"path":124,"seo":728,"stem":125,"__hash__":729},"docs_en\u002Fen\u002F4.admin\u002F4.identityProvider.md",{"type":183,"value":184,"toc":704},"minimark",[185,198,204,207,212,219,222,238,241,243,247,254,257,268,271,273,277,288,291,311,314,316,320,323,326,337,345,347,351,391,396,440,444,516,534,536,540,553,556,558,562,565,569,617,621,663,666,674,677,681,687,690,698,702],[186,187,188,189,193,194,197],"p",{},"This section allows you to configure ",[190,191,192],"strong",{},"how the system authenticates users",". It is intended for ",[190,195,196],{},"application administrators"," and does not require LDAP, Active Directory or SSO expertise.",[199,200],"u-color-mode-image",{"alt":201,"dark":202,"light":203},"Identity Provider page","\u002Fassets\u002Fimg\u002Fdocs\u002FadminTools\u002FidentityProviders\u002Fprovider-dark.png","\u002Fassets\u002Fimg\u002Fdocs\u002FadminTools\u002FidentityProviders\u002Fprovider-light.png",[205,206],"hr",{},[208,209,211],"h2",{"id":210},"internal-identity-provider-default","Internal Identity Provider (default)",[186,213,214,215,218],{},"The system ",[190,216,217],{},"always"," includes an internal Identity Provider.",[186,220,221],{},"Key characteristics:",[223,224,225,232,235],"ul",{},[226,227,228,229],"li",{},"it ",[190,230,231],{},"cannot be deleted",[226,233,234],{},"manages users created directly in the system",[226,236,237],{},"applies configured security rules (password, 2FA, etc.)",[186,239,240],{},"This provider ensures access even if external servers are unavailable.",[205,242],{},[208,244,246],{"id":245},"ldap-identity-providers","LDAP Identity Providers",[186,248,249,250,253],{},"In addition to the internal provider, you can configure ",[190,251,252],{},"one or more LDAP \u002F Active Directory servers",".",[186,255,256],{},"These providers allow you to:",[223,258,259,262,265],{},[226,260,261],{},"authenticate corporate users",[226,263,264],{},"centralize account management",[226,266,267],{},"reuse existing infrastructures",[186,269,270],{},"Each LDAP server is independent.",[205,272],{},[208,274,276],{"id":275},"sso-identity-providers-openid-connect","SSO Identity Providers (OpenID Connect)",[186,278,279,280,283,284,287],{},"The system supports authentication via ",[190,281,282],{},"SSO (Single Sign-On)"," using the ",[190,285,286],{},"OpenID Connect"," protocol.",[186,289,290],{},"Supported provider types:",[223,292,293,299,305],{},[226,294,295,298],{},[190,296,297],{},"Microsoft"," (Microsoft Entra ID \u002F Azure AD)",[226,300,301,304],{},[190,302,303],{},"Google"," (Google Workspace \u002F Google Cloud Identity)",[226,306,307,310],{},[190,308,309],{},"Custom"," (any OpenID Connect-compatible provider)",[186,312,313],{},"SSO providers allow users to log in using their existing corporate or personal accounts, without managing separate credentials in VireoXcube.",[205,315],{},[208,317,319],{"id":318},"identity-provider-list","Identity Provider list",[186,321,322],{},"The main page shows the list of configured Identity Providers.",[186,324,325],{},"For each provider you can:",[223,327,328,331,334],{},[226,329,330],{},"view the provider type (Internal, LDAP, SSO)",[226,332,333],{},"edit the configuration",[226,335,336],{},"delete LDAP and SSO providers",[186,338,339,340],{},"If the list stays empty, the message tells you whether no provider exists yet or the search and the type filters are excluding them all. ",[341,342,344],"a",{"href":343},"\u002Fen\u002Fcomponents\u002Fempty-states","Read more: Empty states",[205,346],{},[208,348,350],{"id":349},"add-a-new-identity-provider","Add a new Identity Provider",[352,353,354,360,377,382,385],"ol",{},[226,355,356,357],{},"Click ",[190,358,359],{},"Add identity provider",[226,361,362,363],{},"Select the provider type:\n",[223,364,365,371],{},[226,366,367,370],{},[190,368,369],{},"LDAP \u002F Active Directory"," for LDAP servers",[226,372,373,376],{},[190,374,375],{},"SSO (OpenID Connect)"," for Microsoft, Google or custom SSO providers",[226,378,356,379],{},[190,380,381],{},"Next",[226,383,384],{},"Fill in the required fields (see below)",[226,386,356,387,390],{},[190,388,389],{},"Add"," to save",[392,393,395],"h3",{"id":394},"ldap-parameters","LDAP parameters",[223,397,398,404,410,416,422,428,434],{},[226,399,400,403],{},[190,401,402],{},"Name"," - LDAP server name",[226,405,406,409],{},[190,407,408],{},"Domain"," - Reference domain",[226,411,412,415],{},[190,413,414],{},"Description"," - Optional description",[226,417,418,421],{},[190,419,420],{},"Protocol"," - LDAP or LDAPS",[226,423,424,427],{},[190,425,426],{},"Port"," - Connection port",[226,429,430,433],{},[190,431,432],{},"Server"," - LDAP server address",[226,435,436,439],{},[190,437,438],{},"Base DN"," - Base DN for user search",[392,441,443],{"id":442},"sso-parameters","SSO parameters",[223,445,446,451,457,461,476,482,488,498,504,510],{},[226,447,448,450],{},[190,449,402],{}," - Display name for the SSO provider",[226,452,453,456],{},[190,454,455],{},"Provider Type"," - Microsoft, Google or Custom",[226,458,459,415],{},[190,460,414],{},[226,462,463,466,467,471,472,475],{},[190,464,465],{},"Authority"," - OpenID Connect authority URL (e.g. ",[468,469,470],"code",{},"https:\u002F\u002Flogin.microsoftonline.com\u002F{tenant-id}\u002Fv2.0"," for Microsoft, ",[468,473,474],{},"https:\u002F\u002Faccounts.google.com"," for Google)",[226,477,478,481],{},[190,479,480],{},"Client ID"," - Application client ID obtained from the provider",[226,483,484,487],{},[190,485,486],{},"Client Secret"," - Application client secret obtained from the provider",[226,489,490,493,494,497],{},[190,491,492],{},"Scopes"," - OpenID Connect scopes (default: ",[468,495,496],{},"openid profile email",")",[226,499,500,503],{},[190,501,502],{},"Default Role"," - Optional role automatically assigned to new SSO users",[226,505,506,509],{},[190,507,508],{},"Default Zone"," - Optional zone automatically assigned to new SSO users",[226,511,512,515],{},[190,513,514],{},"Auto-provision users"," - When enabled, users are automatically created in VireoXcube upon their first SSO login",[517,518,519,520,523,524,527,528,523,531,253],"tip",{},"For Microsoft providers, you can find the Authority URL, Client ID and Client Secret in the ",[190,521,522],{},"Azure Portal"," under ",[190,525,526],{},"App registrations",".\nFor Google providers, configure them in the ",[190,529,530],{},"Google Cloud Console",[190,532,533],{},"APIs & Services > Credentials",[205,535],{},[208,537,539],{"id":538},"edit-an-identity-provider","Edit an Identity Provider",[352,541,542,545,548],{},[226,543,544],{},"Click the provider in the list",[226,546,547],{},"Update the desired parameters",[226,549,356,550,390],{},[190,551,552],{},"Edit",[186,554,555],{},"Changes apply immediately.",[205,557],{},[208,559,561],{"id":560},"password-policies-and-2fa-internal-identity-provider","Password policies and 2FA (Internal Identity Provider)",[186,563,564],{},"For the internal Identity Provider, it is possible to configure password security policies. These settings define the requirements that user passwords must meet.",[392,566,568],{"id":567},"password-length","Password length",[570,571,572,587],"table",{},[573,574,575],"thead",{},[576,577,578,582,584],"tr",{},[579,580,581],"th",{},"Setting",[579,583,414],{},[579,585,586],{},"Default",[588,589,590,604],"tbody",{},[576,591,592,598,601],{},[593,594,595],"td",{},[190,596,597],{},"Minimum length",[593,599,600],{},"Minimum number of characters required",[593,602,603],{},"8",[576,605,606,611,614],{},[593,607,608],{},[190,609,610],{},"Maximum length",[593,612,613],{},"Maximum number of characters allowed",[593,615,616],{},"32767",[392,618,620],{"id":619},"character-requirements","Character requirements",[570,622,623,631],{},[573,624,625],{},[576,626,627,629],{},[579,628,581],{},[579,630,414],{},[588,632,633,643,653],{},[576,634,635,640],{},[593,636,637],{},[190,638,639],{},"Require uppercase",[593,641,642],{},"At least one uppercase letter (A-Z)",[576,644,645,650],{},[593,646,647],{},[190,648,649],{},"Require lowercase",[593,651,652],{},"At least one lowercase letter (a-z)",[576,654,655,660],{},[593,656,657],{},[190,658,659],{},"Require special character",[593,661,662],{},"At least one special character (e.g., !@#$%^&*)",[186,664,665],{},"Password policies are applied:",[223,667,668,671],{},[226,669,670],{},"when creating new users;",[226,672,673],{},"when existing users change their password.",[517,675,676],{},"These rules apply only to users managed by the internal Identity Provider.\nUsers authenticated via LDAP follow the password policies defined on the external server.",[392,678,680],{"id":679},"two-factor-authentication-2fa","Two-Factor Authentication (2FA)",[186,682,683,684,686],{},"In this section, you can also enable or disable ",[190,685,680],{}," for users of the internal Identity Provider.",[186,688,689],{},"When 2FA is enabled:",[223,691,692,695],{},[226,693,694],{},"All users authenticating through this provider must complete 2FA setup on their first login",[226,696,697],{},"A 6-digit code from an authenticator app will be required at each login",[699,700,701],"info",{},"2FA is currently available only for the internal Identity Provider. LDAP and SSO providers do not support 2FA configuration from VireoXcube.",[205,703],{},{"title":705,"searchDepth":706,"depth":707,"links":708},"",2,3,[709,710,711,712,713,717,718],{"id":210,"depth":706,"text":211},{"id":245,"depth":706,"text":246},{"id":275,"depth":706,"text":276},{"id":318,"depth":706,"text":319},{"id":349,"depth":706,"text":350,"children":714},[715,716],{"id":394,"depth":707,"text":395},{"id":442,"depth":707,"text":443},{"id":538,"depth":706,"text":539},{"id":560,"depth":706,"text":561,"children":719},[720,721,722],{"id":567,"depth":707,"text":568},{"id":619,"depth":707,"text":620},{"id":679,"depth":707,"text":680},"Manage identity providers (Internal, LDAP, SSO)","md",null,{},{"icon":126},{"title":123,"description":723},"QffSeBuEtg2lt4Cz0E9Z_hp1-pv-S-rc1g10mRQSHwk",[731,733],{"title":118,"path":119,"stem":120,"description":732,"icon":121,"children":-1},"Viewing and analyzing system activity logs",{"title":128,"path":129,"stem":130,"description":734,"icon":131,"children":-1},"Dashboard template configuration and management",1790665982106]