Cerby-Solutions-Vertical-specific-apps@2xJack Henry SSO login is an advanced authentication feature provided by Jack Henry & Associates, a technology solutions provider for financial institutions. SSO allows users to access multiple applications or services with just one set of login credentials. Instead of remembering separate usernames and passwords for each application, users can log in once and gain access to all integrated services, streamlining the authentication process and enhancing security.

Unfortunately, many corporate applications don't support the SSO standard and can't reap all the benefits. The applications that fall into this category are best called "nonfederated." Nonfederated applications are a new category that is becoming increasingly challenging for businesses to manage and secure effectively, yet increasingly critical for businesses to succeed.

Cerby connects all of your apps to your SSO tools, even if they don't support the SSO standard. In this guide, you'll learn about SSO software, the history, and the benefits.

Streamline access with single sign-on

Not all apps are created equal. Some come with security gaps and complexities that can hinder user adoption and put sensitive data at risk. With Cerby, you can ensure secure and seamless access to all your applications, regardless of their support for standards like SSO.

With Cerby you can

1542756_LP Landing Page_4_012623-1

Close the identity gap

Extend SSO authentication to any legacy or nonfederated app and close the security gap by enforcing access control across all apps, not just those that support identity standards.

1542756_LP Landing Page_5_012623

Universally enforce 2FA

Enable and enforce the most potent form of two-factor authentication (2FA) supported by the application and eliminate the risk of shared access accounts that often have 2FA disabled.

interface-content-book-edit

Eliminate the SSO tax

Stop paying extra for what should be a standard feature of every SaaS application. Move security from being a financial decision to a non-negotiable that doesn’t break the bank.

Get the security of SSO for all your apps.

blue-cta

What is Jack Henry SSO login

Jack Henry & Associates, a leading technology and payment processing services provider in the United States, offers numerous financial solutions, many of which can benefit from single sign-on (SSO) capabilities. Jack Henry SSO integration with identity providers enables users to authenticate themselves one time and get access to multiple applications. As highlighted in the Ponemon Institute study, the main benefit of SSO is that it permits a user to have one set of login credentials—for example, a username and password to access multiple applications. 

Okta is among the most popular identity providers, and their security identity management platform supports seamless SSO integration with various applications, including Jack Henry's solutions. This integration requires configuring the Jack Henry client portal and the Okta platform to communicate effectively.

To start, the administrator must add Jack Henry as a new application in the Okta system. The primary components they’ll be working with are the Single Sign-On URL, Audience URI (SP Entity ID), and the Default Relay State. Once these have been correctly inputted, Okta generates an Identity Provider metadata link, which will be fed back into the Jack Henry system. This completes the Okta authentication process.

The next step is to configure the Jack Henry client portal. The portal is the primary point of contact between the organization and Jack Henry's system. Here, you will input the Okta metadata link into the SSO configuration settings. Once the link is authenticated, Okta becomes the primary identity provider for the portal, and all login requests will be handled by Okta.

This configuration process can also be implemented with other identity providers, such as Microsoft Azure AD. The process is essentially the same, with the identity provider metadata from Azure AD being fed into the Jack Henry client portal and vice versa.

Data management is another vital aspect of any financial institution. To this end, Jack Henry also offers a data warehouse solution. The Jack Henry data warehouse is a sophisticated tool for managing and analyzing vast amounts of data, but it also benefits from SSO integration. The SSO setup ensures secure access to data and facilitates easy and secure data exploration. 

Similar to the client portal, the SSO settings for the data warehouse can be found in the system settings, where the identity provider metadata link from Okta or Azure AD can be inputted.

Another critical element in the Jack Henry ecosystem is the Cognos Analytics tool. To integrate this tool with SSO, users must configure their Jack Henry Cognos login details. 

When the Jack Henry Cognos login is configured correctly, it communicates with the identity provider, be it Okta or Azure AD, allowing seamless authentication of users. The SSO URL, SP Entity ID, and the Default Relay State for the Cognos system must be provided in the identity provider settings, and the corresponding metadata link from the identity provider inputted into the Cognos system settings.

 

Benefits of Jack Henry SSO login

SSO is a user authentication process that permits a user to use one set of login credentials to access multiple applications. The Jack Henry SSO login streamlines the access process for each of a company’s solutions. The benefits of using this system include: 

  • Enhanced user experience: Jack Henry SSO login reduces the number of login prompts for end-users. This creates an enhanced user experience, improves productivity, and boosts overall user satisfaction.
  • Improved security: Using SSO, organizations can use strong authentication methods and enforce strict password policies. SSO also minimizes the risk of phishing, as users have fewer passwords to manage and remember.
  • Reduced administrative costs: Fewer password reset requests often result in lower support costs. Additionally, centralized control facilitates the monitoring and enforcement of compliance guidelines and policies.
  • Efficiency in session management: SSO provides organizations with control over user sessions across multiple applications, which makes it easier to enforce policies on session timeouts and concurrent sessions.

Jack Henry SSO configuration and setup involves a series of steps:

  1. Identity provider setup: This step involves configuring your preferred identity provider, like Microsoft Azure AD or Okta. You'll need to create a new SSO application and input the correct settings for the Jack Henry service.
  2. SAML integration: Security Assertion Markup Language (SAML) is a standard for logging users into applications based on sessions. You’ll need to set up SAML integration by configuring the SSO URL, Audience URI, and the Default Relay State.
  3. Configuration on Jack Henry's side: After setting up the identity provider, you then need to configure the SSO settings on the Jack Henry side. This requires inputting the identity provider’s metadata link into the SSO configuration in the Jack Henry client portal.
  4. User management: Once everything is set up, you can now manage users. Assign users to the SSO application within your identity provider and begin managing these users within Jack Henry’s systems.

While SSO reduces IT help desk calls, there may be instances where users might experience issues. These issues might range from login bugs to sessions not persisting across applications. Jack Henry SSO troubleshooting can help users identify the root causes of such issues. 

 

Jack Henry & Associates 

Jack Henry and Associates offers several solutions for a wide range of use cases. As a recognized leader in the field of financial technology, they provide a comprehensive array of integrated computer systems and services. The Jack Henry software suite consists of a vast range of products designed to cater to various needs within the financial sector.

Among Jack Henry's flagship solutions is Jack Henry SilverLake, a core banking system widely acclaimed for its robust functionality and scalability. Designed to process high-volume transactions, the system provides institutions with a strategic mix of leading-edge technologies and customer-centric functionality, making it a top choice for many mid-tier banks.

Another significant offering from Jack Henry is Jack Henry ProfitStars. This robust suite of products is designed to help financial institutions optimize their performance and growth. It caters to the varied aspects of banking operations, such as asset liability management, profitability, budgeting, financial performance, and risk management.

For institutions seeking to enhance their digital banking capabilities, Jack Henry offers the Jack Henry Banno platform. This digital platform is designed to deliver a consistent, seamless user experience across all digital channels, including online, mobile, and tablet. Jack Henry Banno provides multiple tools that help financial institutions to engage more effectively with their customers and members. The platform includes robust features for marketing, customer support, and more. 

If you’re looking for a good payment processing tool, you might consider the Jack Henry iPay solution. This offers a reliable and secure platform for online bill payment. Jack Henry iPay allows customers to make payments to any individual or business in the United States, providing them with an easy-to-use and convenient way to manage their bill payments.

 

Jack Henry SSO prerequisites

Setting up SSO for Jack Henry's financial solutions can simplify platform access and enhance security. To set up SSO, there are a number of Jack Henry SSO prerequisites that you will need to ensure are in place. The process can seem complex, but it is straightforward once you have these prerequisites ready.

  • Identity provider: Before starting the configuration process, you will need to have a functioning identity provider (IdP) such as Microsoft Azure AD or Okta. The IdP will handle the user authentication and pass the authentication token to the service provider (SP) which, in this case, is the Jack Henry software itself. 
  • Administrative access: To set up SSO, you need administrative access to both the IdP and the Jack Henry systems. This includes access to the Jack Henry partners portal, which is where the SSO configuration is done.
  • SAML enabled: SAML is required for using SSO. Your IdP and the Jack Henry systems must have SAML enabled. If it's not enabled, you will need to contact your IdP or Jack Henry support.
  • Metadata: You need to obtain the metadata from your IdP. This usually comes as an XML file or a URL. The metadata contains information like the IdP's entity ID and the Single Sign-On Service URL, which are necessary for the SSO configuration.
  • SSL certificate: You should also have a valid SSL certificate from a Certificate Authority. This is to ensure that all communication between the IdP and the SP is secure.

With these prerequisites in place, you are now ready to set up the Jack Henry single sign-on. The SSO setup involves configuring the IdP and the Jack Henry systems to communicate with each other. The exact steps depend on your specific IdP, but the process usually involves inputting the IdP metadata into the Jack Henry SSO settings and inputting the Jack Henry SP details into the IdP.

An additional security layer that can be added during the setup process is Jack Henry multifactor authentication (MFA). MFA is a method of authentication where a user is granted access only after successfully presenting two or more pieces of evidence (or factors) to an authentication mechanism.

As part of the SSO setup, it's also a good idea to set up the Jack Henry password manager. The password manager helps manage users' passwords, reducing the risk of password-related security issues.

Cerby is an access management platform that enables many of these types of features. It brings all nonfederated applications into a platform's identity lifecycle. Whether you work with Okta, Azure, or anything in between, you can benefit from eliminating the need for manual password managers. This can be helpful when working with Jack Henry. 

Get the security of SSO for all your apps.

blue-cta