Steps to configure SAML SSO for Cisco Umbrella

About Cisco Umbrella

Cisco Umbrella is a cloud-delivered security solution that provides comprehensive protection against internet threats by integrating DNS-layer security, secure web gateway, and cloud access security broker functionalities, ensuring safe and efficient access to online resources for users on and off the corporate network.

The following steps will help you enable single sign-on (SSO) for Cisco Umbrella from Identity360.

Prerequisites

  1. The MFA and SSO license for Identity360 is required to enable SSO for enterprise applications.
  2. Log in to Identity360 as an Admin or Super Admin.
  3. Navigate to Applications > Application Integration > Create New Application, and select Cisco Umbrella from the applications displayed.
    Note: You can also find Cisco Umbrella from the search bar located at the top.
  4. Under the General Settings tab, enter the Application Name and Description.
  5. Under Choose Capabilities, choose SSO and click Continue.
    Identity360 application configuration General SettingsGeneral Settings of SSO configuration for Cisco Umbrella.
  6. Under Integration Settings, navigate to the Single Sign On tab, and click Metadata Details. You can configure Cisco Umbrella by either uploading the metadata file or entering the details manually.
    • Manual configuration: Copy the Login URL, Logout URL, Entity ID, and Signing Certificate, which will be used during the configuration of Cisco Umbrella.
    • Upload metadata file: Obtain the metadata file to be uploaded during the configuration of Cisco Umbrella in Identity360 by clicking Download from the Metadata field.
     Identity360 application configuration Integration SettingsIntegration Settings of SSO configuration for Cisco Umbrella.

Cisco Umbrella (service provider) configuration steps

  1. Log in to Cisco Umbrella with admin privileges.
  2. From the left menu, expand the Admin section, click Authentication > ENABLE SAML.
    Cisco Umbrella portal viewPortal view of Cisco Umbrella.
  3. Under the Select Umbrella SAML Provider step, select Other and click NEXT.
    Cisco Umbrella SAML SSO stepsSteps to configure SAML SSO for Cisco Umbrella.
  4. Under the Cisco Umbrella Metadata step, click NEXT.
    Cisco Umbrella metadataMetadata of Cisco Umbrella.
  5. For manual configuration, click the Manual Configuration radio button, and paste the Entity ID, Login URL, Logout URL, and Signing Certificate copied from step 6a of prerequisites in the Entity ID, Sign On URL, Logout URL, and X509 Certificate fields, respectively. Click NEXT.
    Cisco Umbrella metadata upload configurationMetadata upload configuration in Cisco Umbrella.
  6. For uploading metadata file, click the XML File Upload radio button, and upload the downloaded metadata file downloaded in step 6b of prerequisites.
  7. Click NEXT.
    Cisco Umbrella manual configurationManual configuration in Cisco Umbrella.
  8. Click TEST CONFIGURATION.
    Cisco Umbrella SSO configuration testSSO configuration test in Cisco Umbrella.
  9. After the test completes, a success message will be displayed.

Identity360 (identity provider) configuration steps

  1. Switch to Identity360's application configuration page.
  2. Enter the Relay State parameter, if necessary.
    Note: Relay State is an optional parameter used with a SAML message to remember where you were or to direct you to a specific page after logging in.
  3. Click Save.
    Identity360 application configurationIntegration Settings of SSO configuration for Cisco Umbrella.
  4. To learn how to assign users or groups to one or more applications, refer to this help document.

Your users will now be able to sign in to Cisco Umbrella through the Identity360 portal.

Note: For Cisco Umbrella, both SP-initiated and IdP-initiated flows are supported.

Steps to enable MFA for Cisco Umbrella

Setting up MFA for Cisco Umbrella using Identity360 involves the following steps:

  1. Set up one or more authenticators for identity verification when users attempt to log in to Cisco Umbrella. Identity360 supports various authenticators, including Google Authenticator, Zoho OneAuth, and email-based verification codes. Click here for steps to set up the different authenticators.
  2. Integrate Cisco Umbrella with Identity360 by configuring SSO using the steps listed here.
  3. Now, activate MFA for Cisco Umbrella by following the steps mentioned here.

How does MFA for applications work in Identity360?

  SSO Integration flow diagram  

Don't see what you're looking for?

  •  

    Visit our community  

    Post your questions in the forum.

     
  •  

    Request additional resources  

    Send us your requirements.

     
Back to Top