US English (US)
FR French
DE German
PL Polish
SE Swedish
FI Finnish

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

English (US)
US English (US)
FR French
DE German
PL Polish
SE Swedish
FI Finnish
  • Log in
  • Home
  • Identity Governance and Administration (IGA)
  • IGA solution library
  • Instructions & guidelines
  • Configure authentication

Configure: ESA Local User (ESM) Login

Learn how to configure Secure Access to authenticate with local ESM users.

Contact Us

If you still have questions or prefer to get help directly from an agent, please submit a request.
We’ll get back to you as soon as possible.

Please fill out the contact form below and we will reply as soon as possible.

  • Service Management
    Matrix42 Professional Solution Matrix42 Core Solution Enterprise Service Management Matrix42 Intelligence
  • Identity Governance and Administration (IGA)
    IGA overview IGA solution library
  • Platform
    ESM ESS2 ESS Efecte Chat for Service Management Integrations Add-ons
  • Release Notes for M42 Professional, IGA, Conversational AI
    2026.1 2025.3 2025.2 2025.1 2024.2 2024.1 2023.4 2023.3 2023.2 2023.1 2022.4 2022.3 Release Information and Policies
  • Other Material
    Terms & Documentation Guidelines Accessibility Statements
  • Services
+ More
    • Service Management

    • Identity Governance and Administration (IGA)

    • Platform

    • Release Notes for M42 Professional, IGA, Conversational AI

    • Other Material

    • Services

Configure: ESA Local User (ESM) Login

Learn how to configure Secure Access to authenticate with local ESM users.

In this article is described instructions for configuring Secure Access component to be able to authenticate with local ESM (Professional and IGA) users. 

Note!

By default Local login configuration is disabled in ESA. When enabled the ESA is passing the User login credentials to ESM, it's also creating own User representation in its own database, because ESA must be aware of any User during login process.  Local users data is stored in ESM database.

 

Step-by-Step Instructions 

  1. Login with ESA Admin (main.admin) to URL domain.com/auth/admin

     
  2. Select correct realm from the top corner
  3. Open Authentication settings from the left side panel and then choose Efecte-login from the list. If Efecte Login is missing add it from Create flow. Name is usually Efecte Login. 




     
  4. Add an Execution 




     
  5. Add new flow to be required.


     
  6. Bind New EFECTE Login form to browser flow (If Bind flow is not offered to Efecte login form it is already in use)




     
  7. Open Realm Settings and tab Themes. Make sure that Efecte login theme is selected


     
  8. Change Realm User profile attributes settings
    Select correct Realm from dropdown
    Go to Realm settings, User profile -tab
     

Modify email, firstName and lastName attributes.

Set those 3 attributes Required: Off.

Save changes to those attributes.

Configuration is now ready.

 

How to test login and logoff

  1. Create local user into ESM, for example:


     
  2. Go to ESA login page and choose "Credentials Login" and “Login with Matrix42 account”

  1. Logout.
  2. Login again with different user, and confirm that you see correct user logged in to solution.
 
 

How to link local user to Entitlements?

If baseline in use you can add Local user to Entitlements from IGA Account template and Attribute called Manually assigned group memberships. Local users, which don't have memberships from directory, must have group memberships assigned in this attribute. Only for administrative use.

If baseline is not in use or is not the newest version you can add the attribute into Person template and edit expression Group info for ESS connector to include manual memberships.

 
 

Troubleshoot

If ESA login works but ESM login not, Check the ESM log called itsm.log (Efecte ESM→ Maintenance→Logs→Download logs→itsm.log)

If ESA login is not working, Check the ESA's server.log (opt/keycloak/standalone/log/server.log) and ESA container log /opt/keycloak/logs/keycloak.log

ESA login is successful, but itsm login screen is displayed. Please check linked article and make sure for example that userlevel is not in use for ESM local users https://docs.efecte.com/iga-support-library/esm-login-process-with-esa

Also note that ESA sends data to ESM in small letters. This means that userID in ESM needs to be in small letters too.

Login is successfully, but local user cannot see anything in ESS.  Please check this article https://docs.efecte.com/iga-configuration-library2/1355364-checklist-user-information-from-esm-to-ess

If ESA javascript mappers need a change, please check this article https://docs.efecte.com/iga-support-library/1812412-esa-custom-javascript-mappers

Login doesn't work and you see http 403 error on browser. Check that your Realms Shibboleth Client has these protocol mappers with other mappers:
urn:mace:dir:attribute-def:principal and com:efecte:ess:user
 

 

 
 

 

 

efecte setup local user login secure access

Was this article helpful?

Yes
No
Give feedback about this article

Table of Contents

Related Articles

  • Configure: Secure Access (ESA) for ESM role assignment

Copyright 2026 – Matrix42 Professional.

Matrix42 homepage


Knowledge Base Software powered by Helpjuice

0
0
Expand