
UNSOLVED
U
ucq_daniel
1 Rookie
•
4 Posts
0
6961
September 17th, 2017 22:00
Single sign on via ADFS/SAML
Hello,
I was hoping someone could assist me getting SSO to work with our on-premises ADFS 4.0 installation. I have some information from Dell around the config:
When configuring Threat Defense with your IdP, you may need the following information (based on your region):
- Sign-On URL/Assertion Consumer Service (ACS)/Entity ID:
- AU: https://login-au.cylance.com/EnterpriseLogin/ConsumeSaml
- EU: https://login-eu.cylance.com/EnterpriseLogin/ConsumeSaml
- US: https://login.cylance.com/EnterpriseLogin/ConsumeSaml
- App ID URI:
Note: The Threat Defense Console uses the user's email address as the User ID. Some IdP providers use a username as the User ID. In this case, you need to map the User ID to the email address in your IdP's settings.
When configuring an IdP (using SAML 2.0) in the Console, you need:
- X.509 certificate
- Login URL for the IdP
To create a custom authentication:
- Log in to the Threat Defense Console.
- Select Settings > Application.
- Select Custom Authentication. By default, Allow Password Login is selected. This allows users to login with a username and password while you configure your SSO. It is recommended to keep this setting enabled until your testing is complete.
- For Provider, select Custom.
- Type or paste your X.509 information in the certificate field.
- Type or paste the Login URL for your IdP.
- Click Save.
I have configured everything and made claim rules to send the data as 'User ID' as specified but it does not seem to work. I can provide saml traces or additional data if required. Does anyone have this working, or know exactly what attributes/data the server requires for a successful login?
Many thanks for any assistance.
Daniel
Thread Summarization
Generate Summary
Responses (0)
Solutions (0)
