Skip to Main Content
Cloud Management and AIOps


This is an IBM Automation portal for Cloud Management, Technology Cost Management, Network Automation and AIOps products. To view all of your ideas submitted to IBM, create and manage groups of Ideas, or create an idea explicitly set to be either visible by all (public) or visible only to you and IBM (private), use the IBM Unified Ideas Portal (https://ideas.ibm.com).

Shape the future of IBM!

We invite you to shape the future of IBM, including product roadmaps, by submitting ideas that matter to you the most. Here's how it works:

Search existing ideas

Start by searching and reviewing ideas and requests to enhance a product or service. Take a look at ideas others have posted, and add a comment, vote, or subscribe to updates on them if they matter to you. If you can't find what you are looking for,

Post your ideas
  1. Post an idea.

  2. Get feedback from the IBM team and other customers to refine your idea.

  3. Follow the idea through the IBM Ideas process.

Specific links you will want to bookmark for future use

Welcome to the IBM Ideas Portal (https://www.ibm.com/ideas) - Use this site to find out additional information and details about the IBM Ideas process and statuses.

IBM Unified Ideas Portal (https://ideas.ibm.com) - Use this site to view all of your ideas, create new ideas for any IBM product, or search for ideas across all of IBM.

ideasibm@us.ibm.com - Use this email to suggest enhancements to the Ideas process or request help from IBM for submitting your Ideas.

Status Not under consideration
Workspace Instana
Categories Access Control
Created by Guest
Created on Aug 31, 2023

Support an alternate/multiple authentication methods

Our team/project, ISV is the underlying function behind w3id and ibmid.  We would like to use ISV based SSO for authenticating to our tenants.   In a scenario we have production issue with the ISV tenant that is used for the Instana SSO, we may not be able to log into Instana to help diagnose the production problem.   
As an ISV SRE, I would like an alternate or additional authentication method to log into our Instana tenant so that we can use Instana to help restore service to our production environment.

Marking priority has High, but if there is currently a solution available that does not require assistance of an Instana support ticket, we can drop it to Medium.  Requiring a support ticket means adding delay to an investigation.

Idea priority High
  • Admin
    Máté Návay
    Reply
    |
    Jul 17, 2024

    Thank you for taking the time to provide your ideas to IBM. We truly value our relationship with you and appreciate your willingness to share details about your experience, your recommendations, and ideas.


    Considering the existing workaround options, IBM has evaluated the request and has determined that it cannot be implemented at this time or does not align with our current strategy or roadmap.


    In 12 months, you will receive a notification that you can resubmit this request for consideration.


    Thank you for bringing your ideas to us. If you have any additional feedback, thoughts or ideas, or if there is anything else I can do, please do not hesitate to reply to this message to continue the conversation.

  • Admin
    Máté Návay
    Reply
    |
    Oct 4, 2023

    Ok, thanks for the clarification, it makes much more sense now.

    The two current options for the short-term would be:
    - use an IdP that can accept multiple different auth sources (like DexIdP https://dexidp.io )
    - use our public APIs to remove and configure a new (alternate) IdP in case the primary is down through a script, as API tokens don't rely on the IdP

    Meanwhile we're assessing what it would take on our backend to support this and prioritize based on that.

  • Admin
    Máté Návay
    Reply
    |
    Sep 4, 2023

    Can you give an example how multiple IdPs are used in any product today?
    The purpose of federated authentication is entirely outsourcing the trust to the IdP, which is also why password logins are disabled, since it could lead to conflicts in allowing or denying login access to someone.

    Since the purpose of using the tool is to monitor the IdP service itself, I would suggest using an alternative login method entirely.