Configure Locker SSO for Epic Rover, Haiku and Canto

Applies to iOS devices only.

Imprivata Mobile Access Management adds authentication to OpenID Connect (OIDC) apps that are configured for OIDC with Imprivata as the Identity Provider (IdP). Authentication shares the MAM user session with Epic Rover, Haiku, and Canto so that a user does not need to enter credentials for authentication to Epic.1.

The app session is secured with the user's personal device passcode.

NOTE:

Locker SSO is not mutually exclusive with Password Autofill. You can still use Password Autofill on other applications, however, you may want to hide the Password Autofill prompt by configuring a Locker Custom Option. Imprivata recommends setting Locker SSO as the default/primary option.

Prerequisites

NOTE:

Supported in MAM 7.3 and later.

Take note of the following prerequisites:

  • Imprivata Locker app for iOS - 4.3 or later.

  • Password Autofill and SSO setting is enabled in MAM console (Admin > Check Out > Password Autofill and SSO).

  • Integration with Imprivata Enterprise Access Management.

    The following EAM dependencies for OIDC integration must be completed:

    • Imprivata appliances are running a maintained release of EAM. For more information, see the EAM Supported Components.

    • Imprivata licensed for Single Sign-On.

    • Epic Rover, Haiku, and Canto apps are added to your Imprivata enterprise.

    • Epic Rover, Haiku, and Canto apps are deployed to a selected set of users.

    • Imprivata users are assigned to a user policy enabled for Single Sign-On.

    • SSO Extension profiles are deployed from your MDM.

  • Epic

  • Key Resources to include during implementation:

    • Customer: Epic Client Systems Analyst (ECSA)

    • Epic: Mobile TS, Client Systems – Web & Interconnect Services

    • Imprivata: Project Manager, Implementation Engineer

Network Requirements

Ensure that your firewall policy is configured to allow communication for Locker SSO.

Add the following hosts to your firewall allow list:

*.cloud.imprivata.com

Face Authentication for Epic Rover, Haiku, and Canto

Beginning in MAM 7.3, as a standard workflow, you can eliminate the device passcode and allow users to use face authentication for Epic Rover, Haiku, and Canto.

  • At device checkout, users are not prompted for a device level passcode. Instead, MAM secures the apps with Face authentication and short inactivity timeouts.

  • Supports any apps that use OIDC.

  • Gives high assurance that the user of the app matches the user who checked out the device.

Requirements

Face authentication for Epic Rover requires the following:

  • Requires an Imprivata Advanced Passwordless Access (APA) license.

Considerations

Application-level timeouts that require the user to re-authenticate are controlled by the individual apps themselves.

There is no way to configure this in either EAM or MAM, and is not affected by EAM user policy grace periods for multi-factor authentication (MFA).

Technical Readiness Checklist

  1. Network Change: Add *.cloud.imprivata.com to firewall allow list

  2. Imprivata EAM:

    Before working with Epic – work with the Imprivata EAM team:

    1. Create the OIDC app within EAM and deploy to users

    2. Confirm the Imprivata Cloud Connection

    3. Generate:

      1. Client ID

      2. Client Secret

      3. Issuer URL

    4. Supply this output to Epic Rover team for E0A Setup

  3. Imprivata MAM:

    Work with the Imprivata MAM team to:

    1. Confirm the required Check Out Admin controls

  4. Epic / Rover Team:

    We recommend you work with Epic to open a Sherlock checklist using Checklist ID 1975.

  5. MDM Team:

    Work with your MDM team to:

    1. Prepare to push eConfig

      1. Configured SSO Extension & OIDC

  6. Clinical User Acceptance Testing:

    NOTE:

    Always perform clinical user acceptance testing before moving the new Rover configuration to production. Your Imprivata services team will assist.

    1. 2 or more devices

    2. 2 or more Epic Rover user accounts

    3. Validate new Locker SSO into Rover and user switch multiple times on both devices

    4. Regression test all other apps with Autofill

  7. Production Rollout:

    Set Locker SSO as the second Primary Device in Epic before moving it to Primary.

  8. Communicate the change ahead of time

  9. Validate that 5+ prod users can use Locker SSO manually

  10. Enable as first Primary Device for all users