Patrick Mackaaij
… is an information distribution coordinator. He is specialized
in technical issues and optimizing processes.

Different login names and passwords for various applications
are a daily annoyance for end users. You can facilitate automatic
logins using SAML (Security Assertion Markup Language) for
employees, customers and partners using the single sign-on
principle. This means they only need to log in once, after which
they can seamlessly use the organization’s applications, even via
the internet.

What is SAML?

The end user can use the same login credentials for all applications

SAML is a technical standard that simplifies automatic logins.

involved in single sign-on. One of SAML’s benefits is that the

Applications outsource the login processing to an Identity

applications in question do not save login details. In practice,

Provider (IdP).

applications often save login credentials in their database in a way

When an end user wants to log in to an application, the application
refers the end user to an IdP to process the login. The IdP identifies
the end user based on their login name, password, and (if applicable)

that is not coded securely enough. News about passwords leaked due
to insufficient security are not uncommon.
For administrators, it is a benefit that logging in is managed

a second factor such as a code sent to their smartphone. The IdP then

centrally. An administrator can block access for all related applications

assigns the user credentials that enable the user to automatically log

from a single point. Instances where this could be useful include

in to the original application. If an end user recently logged in, the

an employee leaving the organization, or a password being entered

IdP immediately fulfills the request. As a result, the user experiences

incorrectly several times. It also makes it possible to centrally manage

applications that support SAML as single sign-on.

password complexity and second factor requests.


SAML and LDAPS instead of VPN

SAML uses a secure internet connection so that your colleagues,

Organizations that outsource the technical management of

customers and partners across the globe can use single sign-on,

applications to application suppliers often choose a VPN connection.

without the disadvantages of a VPN connection. Any exchange of data,

This ‘tunnel’ facilitates automatic logins and data exchange with

such as important contact details, can often be done in a different way,

other systems, such as with TOPdesk SaaS. Opening and maintaining

such as via LDAPS, a stable and safe network protocol.

a VPN connection takes time, however. Installing and changing

LDAPS is safer than VPN. With a VPN connection, the communication

the installation at a later date requires coordination between your

between the end user or the tunnel on one side and the tunnel or

organization and the application supplier. Besides, the tunnel is

server on the other side may be unencrypted. LDAPS encrypts the

temporarily unavailable during maintenance. Think for instance of

entire connection, from server to end user. Short passwords are

changing the pre-shared key (the connection’s ‘password’), which in

common for VPN, while LDAPS uses various lines with a mix of a

practice is rarely changed because of all the surrounding hassle. In

variety of characters thanks to the SSL key used.

daily use, a VPN connection often results in minor disruptions when
one of the intermediate steps has a temporary malfunction.

For your network’s safety, the commonly used Microsoft Active
Directory has offered the possibility of linking a Read Only Domain


Controller to the internet since Windows Server 2008. You can further secure the server

by only allowing connections from specific IP addresses to specific port numbers.


Another option is limiting the traffic to the Domain Controller using stateful inspection.
Are you currently using a VPN connection to TOPdesk SaaS? Contact your account

care of the set-up, such as our sister organization OGD.
TOPdesk supports SAML 2.0 from version 5.5 onwards. In order to use SAML, your
TOPdesk environment should be accessible via the SSL protocol. This could be either

