![gcp-cherry-pick-bot[bot]](/assets/img/avatar_default.png) 7927392100
			
		
	
	7927392100
	
	
	
		
			
			website/docs: add info about invalidation flow, default flows in general (#11800) * restructure * tweak * fix header * added more definitions * jens excellent idea * restructure the Layouts content * tweaks * links fix * links still * fighting links and cache * argh links * ditto * remove link * anothe link * Jens' edit * listed default flows set by brand * add links back * tweaks * used import for list * tweak * rewrite some stuff * format * mangled rebase, fixed * bump --------- Signed-off-by: Jens Langhammer <jens@goauthentik.io> Co-authored-by: Tana M Berry <tanamarieberry@yahoo.com> Co-authored-by: Tana M Berry <tana@goauthentik.com> Co-authored-by: Jens Langhammer <jens@goauthentik.io>
		
			
				
	
	
	
		
			3.4 KiB
		
	
	
	
	
	
	
	
			
		
		
	
	title
| title | 
|---|
| Manage applications | 
Managing the applications that your team uses involves several tasks, from initially adding the application and provider, to controlling access and visibility of the application, to providing access URLs.
Add new applications
Learn how to add new applications from our video or follow the instructions below.
Video
Instructions
To add an application to authentik and have it display on users' My applications page, you can use the Application Wizard, which creates both the new application and the required provider at the same time.
- 
Log into authentik as an admin, and navigate to Applications --> Applications. 
- 
Click Create with Wizard. (Alternatively, use our legacy process and click Create. The legacy process requires that the application and its authentication provider be configured separately.) 
- 
In the New application wizard, define the application details, the provider type and configuration, and then click Submit. 
- 
To manage the display of the new application on the My applications page, you can optionally define the bindings for a specific policy, group, or user. Note that if you do not define bindings, then all users have access to the application, For more information, refer to authorization. 
Authorization
Application access can be configured using (Policy) bindings. Click on an application in the applications list, and select the Policy / Group / User Bindings tab. There you can bind users/groups/policies to grant them access. When nothing is bound, everyone has access. You can use this to grant access to one or multiple users/groups, or dynamically give access using policies.
By default, all users can access applications when no policies are bound.
When multiple policies/groups/users are attached, you can configure the Policy engine mode to either:
- Require users to pass all bindings/be member of all groups (ALL), or
- Require users to pass either binding/be member of either group (ANY)
Hide applications
To hide an application without modifying its policy settings or removing it, you can simply set the Launch URL to blank://blank, which will hide the application from users.
Keep in mind that users still have access, so they can still authorize access when the login process is started from the application.
Launch URLs
To give users direct links to applications, you can now use a URL like https://authentik.company/application/launch/<slug>/. If the user is already logged in, they will be redirected to the application automatically. Otherwise, they'll be sent to the authentication flow and, if successful, forwarded to the application.
Backchannel providers
Backchannel providers can augment the functionality of applications by using additional protocols. The main provider of an application provides the SSO protocol that is used for logging into the application. Then, additional backchannel providers can be used for protocols such as SCIM and LDAP to provide directory syncing.
Access restrictions that are configured on an application apply to all of its backchannel providers.