Authentication

The authentication methods, and SCIM interface, used to access Field First are as follows:

The diagrams below provide an example of the capabilities which can be accessed via Field First, this is not an exhaustive list of the Totalmobile capabilities.

For further details refer to Totalomobile's Authentication Recommendations .

Single Sign-On via Field First’s Identity Server

These are the steps carried out when using Field First’s Identity Server:

  1. User logs in to Field First with their Active Directory username and password.

  2. The Single Sign-On token checks the login details against the Field First Identity Server.

  3. When the Field First Identity Server confirms the login details are correct, it checks to see which capabilities they have access to and automatically logs them in.

Single Sign-On via Federated Authentication

These are the steps carried out when using your organisations Identity Server to federate against:

  1. The user logs into Field First with their Active Directory username and password.

  2. A Single Sign-On token is sent to the Field First Identity Server.

  3. The Field First Identity Server checks the users login details against your organisations Identity Server, and confirmation of the login details being correct is returned to the Field First Identity Server.

  4. The Field First Identity Server checks to see which capabilities they have access to and automatically logs them into them.

System for Cross-domain Identity Management (SCIM) Interface

These are the steps carried out when using a SCIM interface:

  1. An employee is added, updated, or deleted in your Identity Server.

  2. These changes are pushed from your Identity Server to the Field First Identity Server.

  3. The Field First Identity Server pushes these changes to your capabilities.

  4. The super user then updates the users permissions within the capability.

For further details refer to Configure Your SCIM - Azure Entra ID.

Authentication Recommendations

The following are Totalmobile's authentication recommendations for each capability accessed through Field First: