Anchanto Operations Experience Management (OXM) provides centralized authentication management through Microsoft Entra ID Single Sign-On (SSO) and native Email One-Time Passcode (OTP/2FA) verification. Configuring these access controls secures administrative and seller portal access, streamlines identity management, and reduces reliance on vulnerable static credentials.
Prerequisites:
Permissions: Platform Administrator access (for Tenant Admin Portal settings) or Seller Administrator access (for Seller Portal settings).
Identity System: An active Microsoft 365 / Microsoft Entra ID (formerly Azure Active Directory) environment.
IT Administrative Access: Privileges to register applications and generate API credentials within the Microsoft Entra admin center.
Account Alignment: Every targeted user must have an active Anchanto OXM account matching their exact Microsoft work email address.
Mail Relay & Firewall Settings: Organizational inbox rules permitting automated 6-digit OTP delivery emails.
Important: For enabling SSO, all users must use email addresses from a single organizational domain. If your users currently use multiple email domains, please discuss this with your Account Manager before initiating SSO setup.
Step-by-Step Instructions
Initiating SSO Setup in Anchanto OXM
Go to Admin Portal → Preferences → SSO Configuration (for Head-Office/Tenant Admins) or Seller Portal → Self Services → Configurations → SSO Configuration (for Seller Admins) → The system opens the SSO configuration page.
Click Enable SSO → The system activates the configuration fields and automatically generates a unique, organization-specific Redirect URI.
Copy the Redirect URI → The unique redirect URL is saved to your clipboard for use in the Microsoft Entra admin center.
Registering the Platform in Microsoft Entra ID
Go to Microsoft Entra admin center → Sign in as an IT Administrator → The Microsoft Entra administration dashboard opens.
Go to App Registrations → Click New Registration → The application registration form opens.
Enter a recognizable application name into the Name field → Paste the copied Redirect URI into the Redirect URI (Sign-in reply address) field → Click Register → The application profile is created and displayed.
Go to Overview → Copy the displayed Application (Client) ID and Directory (Tenant) ID values → The IDs are stored for entry into Anchanto OXM.
Go to Certificates & secrets → Click New client secret → Enter a description and expiry period → Click Add → Copy the generated Client Secret value immediately → The secret value is saved for platform entry.
Completing Anchanto OXM SSO Integration
Go to Anchanto OXM → SSO Configuration screen → The Provider Details input section is displayed.
Enter Microsoft Azure into the SSO Provider Name field → The system identifies the authentication provider type.
Enter the copied Directory (Tenant) ID into the Provider Tenant field → The tenant directory is linked to the platform.
Enter the copied Application (Client) ID into the Client ID field → The registered application identity is bound to the platform.
Enter the copied secret value into the Client Secret field → The authentication handshake credentials are secured.
Click Save → The system activates SSO authentication for the target portal.
Go to Anchanto OXM Login Screen → Click Login with SSO → The system redirects to Microsoft's sign-in page, authenticates your account, and returns you to the active dashboard.
Enabling and Managing Email OTP (Two-Factor Authentication)
Email OTP enforces a mandatory secondary authentication layer for traditional username-and-password logins.
Configurable Enforcement Levels
Email OTP operates using a clear, hierarchical switch structure:
Feature Switch: Controlled globally by Anchanto for the entire tenant.
Tenant-Wide Switch: Set by Tenant Administrators to enforce OTP across all users in the tenant, including the Admin Portal.
Per-Seller Switch: Set by Tenant or Seller Administrators to enforce OTP for everyone under a specific seller account. Go to Admin Portal → Customers → Manage Customers → Edit Customer → Basic Information → Select Enable 2FA check box (and Enable SSO Feature if configuring SSO on behalf of a seller).
Per-User Switch: Set by user managers on individual profile records to enforce OTP for a single user.
Note: Administrator impersonation logins used by support staff are permanently exempt from Email OTP verification prompts.
Logging In with Email OTP Verification
Go to Anchanto OXM Login Screen → Enter Email ID and Password → Click Sign In / Login → The system validates primary credentials and dispatches a 6-digit numeric verification code to your registered email inbox.
Open your email client inbox → Copy the 6-digit verification passcode → The passcode is ready for authentication entry.
Go to Anchanto OXM OTP Entry Screen → Enter the 6-digit code into the Enter OTP fields → Click Verify OTP → The system validates the code and logs you into the dashboard.
System Operational Rules & Parameters
Passcode Format: 6-digit numerical code.
Code Expiration: 5 minutes from generation.
Maximum Verification Attempts: 3 failed entries per code.
Maximum Resend Requests: 3 code re-issuances per login session.
Session Reset Rule: Exceeding 3 invalid attempts or 3 resends locks the active token. Click Back to Login Page and re-enter your password to generate a fresh verification cycle.
SSO Bypass of Email OTP: Users logging in via Login with SSO will not receive an Email OTP prompt, as Anchanto OXM defers multi-factor authentication requirements directly to Microsoft Entra ID policies.
| If the system shows this error | Follow these steps to fix it |
Microsoft Account Mismatch Failure (User cannot log in via SSO despite valid Entra credentials) | Verify that the user's Microsoft work email address matches their registered Anchanto OXM account email address exactly, including capitalization and domain syntax. If mismatched, update the profile email in Anchanto OXM. |
Invalid Client Secret / Unauthorized Redirect during SSO setup | Confirm that the Redirect URI generated by Anchanto OXM matches the Redirect URI registered in the Microsoft Entra admin center character-for-character. Verify that the Client Secret in Microsoft Entra ID has not expired, and re-enter valid credentials if necessary. |
OTP Code Expiry / Timeout ("Code expired") | OTP passcodes stop working 5 minutes after issuance. Click Back to Login Page, re-enter your username and password, and submit the fresh 6-digit code immediately upon receipt. |
OTP Delivery Delays (No code received in inbox) | 1. Check your email account's Spam, Junk, and Promotional folders.
2. Wait for the on-screen countdown timer to finish so the Resend OTP button becomes active, then request a new code.
3. Ensure your IT administrator has whitelisted automated mail delivery from Anchanto. |
Exceeded Attempt Limits ("Maximum attempts reached") | Entering an incorrect code 3 times locks out that specific OTP token. Click Back to Login Page to restart the sign-in process from the password screen, which generates a brand-new code and resets attempt limits. |
Logged into Wrong Microsoft Account during SSO attempt | Sign out of all active Microsoft browser sessions or use a private/incognito browsing window. Click Login with SSO again and select the correct organizational account when prompted by Microsoft. |
Comments
0 comments
Please sign in to leave a comment.