General Settings

On the General Settings page, you can configure account types, server URL, and login styles for your SSO Server.

Account Type

Select the types of user accounts that can access SSO services.

To allow local users to sign in via SSO:

  1. Make sure that your Synology NAS contains local users with the same usernames as those in your client applications (hereafter "apps").
  2. Select Domain/LDAP/local from the Account type drop-down menu.

To allow directory users to sign in via SSO:

  1. Join your Synology NAS to a directory service at Control Panel > Domain/LDAP.
  2. Make sure your apps are the clients of the same directory service. If your apps do not support directory client settings, you can import directory users to the apps.
  3. Select Domain/LDAP/local or Domain/LDAP from the Account type drop-down menu.

Server URL

This URL is the location of your Identity Provider (IdP). It is used to generate other IdP information, such as the IdP metadata (SAML) and well-known URL (OIDC).

Make sure to set up the server URL before activating SSO services for your apps.

Note:

  • The server URL cannot be an IP address. It should be a domain name that can be accessed over HTTPS and has a valid TLS certificate.
  • The server URL does not support Synology QuickConnect.
  • If there are any changes to the server URL, make sure to update IdP information on your apps.

Login Settings

Click Settings to customize the login style and various connection settings for your SSO portal. You can also access these settings at Control Panel > Login Portal > Applications > Synology SSO.

Account Type
Server URL
Login Settings