Skip to main content

HelloID

Show/hide IdPs (client restrictions)

By default, HelloID displays all available Identity providers (IdPs) on the login screen. This can be confusing for end users. Resolve this with client restrictions, which conditionally show/hide IdPs.

For this example, users on the organizational network, using domain-joined equipment, should be automatically logged in with integrated Windows authentication. Show only Agent-based authentication for all other instances.

Show an IdP
  1. Go to Security > Authentication > Identity Providers.

  2. For the relevant IdP, click Edit.

    For this example, we'll select our ADFS IdP.

    2022-10-27_11-28-47.jpg
  3. Go to the Client Restrictions tab.

  4. For the Action, select Show.

  5. Enable the Use IP Restriction toggle.

  6. In the IP Ranges field, enter the IP address for the organization's public-facing IP. For multiple addresses, separate each with a comma. For a range, use a hyphen. For example: 66.123.1.0-66.123.1.254.

  7. Enable the Use Source Restriction toggle. Select the browser/device-types allowed to use this authentication method.

  8. Click Save.

    2022-02-18_11-57-39.png
Hide an IdP
  1. Go to Security > Authentication > Identity Providers.

  2. For the relevant IdP, click Edit.

    For this example, we'll select our Azure AD IdP.

    2022-10-27_11-37-28.jpg
  3. Go to the Client Restrictions tab.

  4. For the Action, select Hide.

  5. Enable the Use IP Restriction toggle.

  6. Enter the same IP range as before.

  7. Click Save.

    2022-10-27_11-38-34.jpg
  8. Repeat these steps to hide other IdPs, such as the Local IdP.

Users will now only see relevant IdPs. Irrelevant IdPs will be hidden from the HelloID login screen.