Local IdM allows for automatic synchronization of users and rights to MitID Erhverv. The automatic synchronization is achieved through a IdM API which means that the users are created in both MitID Erhverv and your local IdM-system. This gives you less administration and higher security. With Local IdM light, a user will have to activate their user profile with their private MitID.
You enter into an agreement with MitID Erhverv regarding an integration to IdM through the following two steps:
An IdM solution in combination with Local IdP (which has been NSIS reviewed), will give you full control of users, rights and authenticators - but also the full responsibility of these.
This solution differs from IdM light, as described above, in the sense that users will be able to use locally issued authenticators instead of MitID authenticators. This offers a number of advantages for the users, e.g. they will not need to activate their user profile with their private MitID. However, it is required that the Local IdP solution is NSIS approved.
As with Local IdM, users and right will automatically synchronise to MitID Erhverv. You will benefit from:
Due to the NSIS review there are high security requirements and increased costs for certifications and annual audit.
Read more about Local IdP
Options |
Local IdM light |
Local IdM + IdP |
---|---|---|
Automatic synchronization to NemLog-in |
X | X |
Local identity assurance |
X | |
Certification and annual audit |
X | |
Local network password and own two-factor authenticator |
X | |
Local help - e.g. when forgotten password |
X | |
Single sign-on experience for users |
X |
This guide is a help to organisations wishing to integrate their organisations IdM-system with MitID Erhverv. The guide describes what you need to consider and execute in order to establish the integration.
It requires technical development to establish the integration. It is therefore adviced that you use developers experienced within your IdM-system and with knowledge related to developing an API integration.
Choose the form of integration between your IdM-system and MitID Erhverv, which suits your needs.
You will have to complete a NSIS review, if you decide to implement Local IdM in combination with Local IdP.
When connecting your Local IdP you will have to document that the requirements of the NSIS level to which the IdP is approved (Low/Substantial/High) are met. You will have to prepare an audit statement as well as a management statement as documentation.
Consider the options for integration between your IdM-system and the IdM API.
In the pre production environment, you can find information on how to create test data. Using the pre production environment does not require that you are connected to MitID Erhverv.
Test that your local solution works, so you are able to create users and assign them rights in MitID Erhverv.
You have to request access to the IdM API in the production environment.
Once you have connected your organisation to MitID Erhverv, you can import your users and other data from NemID medarbejdersignatur. This way, you will transfer relevant administrative roles, billing information, the users and their associated rights to MitID Erhverv.
Alternatively, you can create users directly in MitID Erhverv based on your IdM data. However, you should be aware that you must supply the RID numbers (from NemID medarbejdersignatur) when creating the users in order for them to maintain their current rights. In addition, you must manually assign administration roles and enter billing information, as this is not listed in your IdM system.
One you have connected to MitID Erhverv, you can log on and issue a system certificate. You need the system certificate for authentication toward your IdM API service.
Set your solution in production. Authentication is carried out through the system certificate.