Domain
Overview
The Domain section of the Admin Console displays domain-level settings and allows administrators to manage users, security policies, access controls, and integrations. To view Domain settings, navigate to Admin from BioInsight Platform and select Domain from the left navigation menu.
The Domain settings page contains the following sections, accessible from the left navigation submenu:
Usage reports
Generate reports on user sessions, login activity, and workgroup events.
Sessions
Configure idle session timeout, JWT expiration, and API key settings.
User management
Manage domain users, allowed emails, and service accounts.
Access
Restrict domain access by IP address or CIDR range.
Collaboration
Configure collaboration domain namespaces.
Roles
Create and manage custom roles with unique permission settings.
Authentication
Configure the authentication type (Default or SAML SSO).
DNS domain
Verify DNS domain ownership for SSO configuration.
About
View the domain name, namespace, and ID.
About
The About section displays basic information about the domain: the domain Name, Namespace, and ID. Click Change name to update the domain display name.

Usage Reports
The Usage reports section allows you to generate reports on domain activity.

Select a report type:
General Usage Report
User sessions, last login details, registration date, and usernames.
Login Report
Account activity including client IP addresses, applications accessed, event types, and user emails.
Workgroup Report
Workgroup activities, including event data for actions performed by each user.
Select a Date range and enter the email addresses of the Recipients who should receive the report. Click Generate reports to submit.
Usage reports can only be generated for the last 90 days. For information older than 90 days, contact Illumina Support.
Sessions
The Sessions section allows you to configure session timeout and API key settings.

Idle Session and JSON Web Token (JWT)
Session timeout
The number of minutes a session can be idle before it times out. Accepted values are 5–60 minutes. Set to -1 to disable.
JSON Web Token (JWT) expiration
The duration before the JWT token expires. Accepted values are 120–10,080 minutes (2 hours to 7 days).
API Keys
API keys expiration
The number of days before an API key expires. Set to -1 to disable expiration.
Max active API keys
The maximum number of active API keys a user can have at the same time.
Click Edit to modify these settings.
User Management
The User management section contains three tabs: Users, Allowed emails, and Service accounts.
Users
The Users tab displays a list of all domain users with their name, email, domain role, and action buttons.

The Domain owner is displayed at the top of the page. Use the Search username box and All users dropdown to filter by name or role.
Each user row shows:
Name
The user's display name. Click to view user details.
The user's email address.
Domain role
Admin or User.
Actions
View user details or delete the user.
Change Domain Owner
To change the domain owner, click Change owner at the top of the Users tab.

The domain owner is the primary administrator and main point of contact for the domain. They receive monthly emails about BIC balances and are automatically assigned to any new orders placed for the domain. Enter the new owner's email address and click Change owner.
Assigning a domain owner automatically makes them a domain administrator. The previous domain owner will remain a domain administrator.
Invite Users
To invite users to the domain, click + Invite at the top of the Users tab. Enter one or more email addresses to send domain invitations.
Allowed Emails
The Allowed emails tab controls which email addresses can join the domain.

Allowed email addresses
Users can join the domain if their email exactly matches one of these addresses.
Allowed email suffixes
Users can join the domain if their email contains one of these suffixes (do not include the @ symbol).
It is not recommended to allow common email suffixes such as gmail.com.
Click Edit to add or remove allowed emails and suffixes.
Service Accounts
The Service accounts tab displays special accounts used by applications or services to interact with the domain without requiring a user to log in.

Toggle Enable service accounts to allow or block service accounts. When disabled, existing service accounts are blocked and new ones cannot be created.
The service accounts table shows each account's PGUID, status, activation date, expiration date, associated application, and action buttons. Click the manage icon in the Actions column to view the account's state and API keys.
Access
The Access section allows you to restrict domain access by IP address or CIDR range.

Select a method of access management:
Create an allow-list for IP addresses/CIDR to allow access — Only the specified addresses will be allowed.
Create a block-list of IP addresses/CIDR to block access — The specified addresses will be blocked.
Enter IP addresses or CIDR ranges separated by commas (e.g., 192.10.10.1, 192.255.10.*, 192.10.10.0/32). Click Edit to modify these settings.
Collaboration
The Collaboration section allows you to configure the collaboration domain namespaces for inviting users via Collaborative Enterprise.

Enter a domain namespace and click Edit to add it to the allowed list. Users from these namespaces can be invited to workgroups via Collaborative Enterprise.
Roles
The Roles section allows domain administrators to create and manage custom roles with unique permission settings that provide access control within workgroups.
Be cautious when applying custom roles — incorrect setup may lead to restricted access and unexpected issues.
Use the Search box to filter by application name or role name. The table displays each role's name, associated application, description, type (System or Custom), last modified date, and available actions.
Click a role name to view its detailed permissions. To create a new role, click + Create role, select an application, enter a role name and optional description, and select at least one permission.
Authentication
The Authentication section allows you to configure the domain's authentication method.

Authentication Type
Default
The Illumina Authentication System manages user credentials.
SAML
Users are redirected to your Identity Provider (IdP) to authenticate via SAML 2.0 (see Single Sign-On below).
Multi-Factor Authentication (MFA)
If your Authentication Type is configured to SAML, MFA settings are managed by your SAML provider.
Require MFA
Enable or disable multi-factor authentication for the domain.
Users need to configure MFA within
The number of days users have to complete MFA setup before it becomes mandatory.
Lock user account after
The number of unsuccessful MFA attempts before the account is locked.
Click Edit to modify authentication settings.
Single Sign-On (SSO)
SSO requires an Illumina BioInsight Platform (formerly Connected Software) domain subscription. It is not available for BaseSpace Free Trial or BaseSpace Professional accounts, which do not include a domain.
To enable logging into the platform using your organization's identity provider (IdP), configure SAML in the Authentication section.
To configure SSO, follow these steps:
Verify your organization's DNS domain in Illumina BioInsight Platform (formerly Connected Software).
Create a SAML 2.0 application in your IdP.
Configure ICS with your IdP metadata and attribute mappings.
Switch your domain authentication to SAML and test.
Prerequisites
An active Illumina domain subscription
A domain administrator account for your Illumina domain
Access to your IdP to configure the SP application
Your IdP configurations:
Metadata XML
SAML Attributes for EmailId, firstName, LastName
Configure DNS Domain
Step 1: Create DNS Domain record
Go to the Admin Console for your Illumina domain, and navigate to the Domain tab.
Navigate to the DNS domain menu.

Enter your domain (e.g., company.com) and click Add.
Copy the TXT record value for the new entry.
Step 2: Verify DNS Domain
To confirm domain ownership, add a TXT record to your Domain Name System (DNS) host using the TXT Record Value. DNS propagation can take up to 72 hours. Illumina BioInsight Platform (formerly Connected Software) automatically checks for the record during this time.
To add your TXT record to AWS, see Creating records by using the Amazon Route 53 console.
Wait up to 72 hours for TXT record verification.
After the record is live, go to DNS domain in the Admin Console and select Verify.
To add your TXT record to Google Cloud DNS, see Verifying your domain with a TXT record.
Wait up to 72 hours for TXT record verification.
After the record is live, go to DNS domain in the Admin Console and select Verify.
To add your TXT record to GoDaddy, see Add a TXT record.
Wait up to 72 hours for TXT record verification.
After the record is live, go to DNS domain in the Admin Console and select Verify.
Sign in to your domain host.
Add a TXT record to your DNS settings and save the record.
Wait up to 72 hours for TXT record verification.
After the record is live, go to DNS domain in the Admin Console and select Verify.
Connect SSO
Step 1: Create SSO connection in IdP
The Illumina BioInsight Platform (formerly Connected Software) service provider (SP) application uses the following configuration:
Entity ID:
https://login.illumina.com/saml-service/saml/metadataACS (Assertion Consumer Service) URL:
https://login.illumina.com/saml-service/saml/SSOBinding: HTTP-POST
NameID Format:
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
Sign in to your Okta account and open the Admin portal.
Select Administration and then Create App Integration.
Select SAML 2.0, then Next.
Name your app "Illumina BioInsight Platform".
Optional: Upload a logo.
Paste the service provider configuration values from above:
ACS URL → Single Sign On URL
Entity ID → Audience URI (SP Entity ID)
Configure the following settings:
Name ID format:
EmailAddressApplication username:
EmailUpdate application username on:
Create and update
Under Attribute Statements, enter the following Name → Value attributes. Make sure the Name format is set to "URI Reference."
email → user.email
first → user.firstName
last → user.lastName
Select Next.
Select the This is an internal app that we have created checkbox.
Select Finish.
Sign in to Microsoft Entra (formerly Azure AD).
Select Default Directory > Add > Enterprise Application.
Choose Create your own application, name it "Illumina BioInsight Platform", and choose Non-gallery.
After creating your app, go to Single Sign-On and select SAML.
Select Edit on the Basic SAML configuration section.
Edit Basic SAML configuration and paste values from above:
Entity ID → Identifier
ACS URL → Reply URL
Save the configuration.
From the SAML Signing Certificate section, download the Federation Metadata XML.
Step 2: Connect Illumina BioInsight Platform (formerly Connected Software) to your IdP

Complete the integration by pasting your IdP values into Illumina BioInsight Platform:
Go to the Admin Console for your Illumina domain, and navigate to the Domain tab.
Navigate to the Authentication menu and enable the SAML Authentication Type.
In Okta, select your app and go to View SAML setup instructions.
Copy the Identity Provider Single Sign-in URL.
Copy and paste the IDP Metadata into a text editor. Save the file.
Return to the Illumina BioInsight Platform Admin Console.
Paste the Sign-in URL in the IdP URL field.
Upload the IDP Metadata file to the "Select SAML Configuration File" file uploader.
Add the SAML Attribute Mappings:
EmailId → email
Last name → last
First name → first
Review and select Save.
In Entra ID, copy the Login URL from the Configuration URLs.
Return to the Illumina BioInsight Platform Admin Console.
Paste the Login URL in the IdP URL field.
Upload the Federation Metadata XML file to the "Select SAML Configuration File" file uploader.
Add the SAML Attribute mappings:
EmailId → http://schemas.xmlsoap.org/ws/2005/05/identity/claims/userPrincipalName
Last name → http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
First name → http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenName
Review and select Save.
Allow 15 minutes for the Illumina Service Provider to update with the provided information. To confirm SAML configuration changes, attempt to log in using a qualified email (e.g., @company.com).
Passwords
Deprecated — PCN 2026-1866
Domain password policy settings have been deprecated. Minimum password complexity across the Illumina BioInsight Platform now meets or exceeds any previously configurable policy, so these settings are no longer available.
To manage custom password settings, configure Single Sign-On (SSO) for your domain.
Last updated
Was this helpful?

