Enable Channel Authentication in Experience Manager
Overview
This page explains how to require authentication for CMS users previewing protected channels or pages in Experience Manager.
When to Use
Enable channel authentication when you want CMS users to authenticate before previewing channels or pages that are protected by delivery tier authorization.
Background
By default, Experience Manager allows CMS users to preview any channel without authentication, even if the channel or specific pages require authentication for site visitors. This behavior is controlled by the hst:channelmanagersiteauthenticationskipped property in the repository configuration.
You can override this default and require authentication for CMS users in preview mode. This ensures that previewing a protected channel or page in Experience Manager follows the same authentication rules as site visitors.
For more information about delivery tier authorization and authentication, see:
Prerequisites
- Access to the JCR repository configuration.
- Appropriate permissions to modify channel configuration nodes.
Implementation Steps
- Locate the
/hst:hst/hst:hostsnode in the JCR repository. - Set the
hst:channelmanagersiteauthenticationskippedproperty tofalse.
Example configuration:
/hst:hst: /hst:hosts: hst:channelmanagersiteauthenticationskipped: false
Verification
After updating the configuration:
- Log in to Experience Manager as a CMS user.
- Attempt to preview a protected channel or page.
- The system should now require authentication before allowing access to the preview.