Configure Authentication

By default, Meridian Enterprise identifies a user by single sign-on (the current user's Windows account name) and does not prompt the user to log on when they open a vault. Meridian also supports explicit authentication to open a vault with any Meridian Enterprise client application including Application Integration, the application links, and Local Workspace actions.

When authentication is required, users are shown the Open Vault dialog. The user must type the same Windows account name and password as the account currently logged on to Windows. Authentication only succeeds if the credentials match. If so configured, failure to correctly type the credentials within the allowed number of attempts will prevent the user from opening any vault until the correct credentials are typed.

Note:

Enabling operating system authentication requires that the audit log also be enabled to log the authentication results. The audit log can be stored in a database separate from Meridian Enterprise as described in the Accruent Meridian Enterprise Administrator's Guide. If your environment also includes Meridian Enterprise Server, the audit log can also be stored in its database as described in Configure the connection to Meridian Enterprise Server.

To configure a vault's authentication settings:

  1. In Configurator, expand Environment in the configuration tree and select Vault Settings.

    The vault's settings appear in property pages in the right pane.

  2. Click the Authentication tab.

    The current authentication options are shown.

  3. Click Edit.

  4. Click options or type values using the descriptions in the following table.

  5. Click OK.

Authentication options
Option Description

Authenticate logon credentials with the operating system

Authenticates the user's credentials with the operating system to authorize opening the current vault.

Note:

If this option is enabled after a vault has already been published as a web location for PowerWeb, access will be denied to users until the vault is republished as a PowerWeb location.

Logon retries

The number of authentication attempts to allow users before locking their account.

Lock user when all retries have failed

Locks the user's account to prevent further access to documents. The identity of the user or their credentials should then be verified by a system administrator. The account must be unlocked using Meridian Enterprise Administrator or the Meridian Enterprise Server Administration Console tools.

Default domain name

The Windows domain within which the users of this vault should be authenticated. If this option is left blank, users must enter the domain name when they enter their user name, for example, MYDOMAIN\MyName.

Remember user name

Retains the user name (but not the password) for subsequent authentication requests.

Use electronic signatures on workflow transitions

Requires electronic signatures when workflow transitions are performed for which signatures have been enabled as described in Configure Document Type Workflow

and Configure Transition Authorization.

Show reason page

If enabled, shows a dialog box when documents are electronically signed that contains configurable disclaimer text and prompts the user to select a reason why they are signing the documents.

This lookup list

The name of an existing lookup list from which to show the reasons for signing.

This expression

A VBScript expression that returns an array of reason strings to show for signing.

Note:

The expression should not reference document or folder objects because the dialog box is shown only once for the entire batch of documents even if only one is selected and it is shown before the selection is processed. The vault object is available but provides properties and methods that are of limited value in this scenario.

Disclaimer

Text to show in the dialog box, for example:

By entering your user ID and password, you are verifying this document's content and properties congruent with your responsibilities. As such, you have reviewed and are approving the document for it's intended use.

Remember user name for batches of electronic signatures

Retains the user name (but not the password) for each electronic signature required by a batch of documents.

Important!

If the Authenticate logon credentials with the operating system option is enabled, the vault is published as a PowerWeb location, and the website is configured with Basic authentication, unauthorized user access to the vault cannot be prevented completely. We do not recommend using that authentication method and recommend that it be set to Windows integrated authentication instead.

2021 R2