Steps to configure SAML SSO for Cisco Umbrella
About Cisco Umbrella
Cisco Umbrella is a cloud-delivered security solution that provides comprehensive protection against internet threats by integrating DNS-layer security, secure web gateway, and cloud access security broker functionalities, ensuring safe and efficient access to online resources for users on and off the corporate network.
The following steps will help you enable single sign-on (SSO) for Cisco Umbrella from Identity360.
Prerequisites
- The MFA and SSO license for Identity360 is required to enable SSO for enterprise applications.
- Log in to Identity360 as an Admin or Super Admin.
- Navigate to Applications > Application Integration > Create New Application, and select Cisco Umbrella from the applications displayed.
Note: You can also find Cisco Umbrella from the search bar located at the top.
- Under the General Settings tab, enter the Application Name and Description.
- Under Choose Capabilities, choose SSO and click Continue.
General Settings of SSO configuration for Cisco Umbrella.
- Under Integration Settings, navigate to the Single Sign On tab, and click Metadata Details. You can configure Cisco Umbrella by either uploading the metadata file or entering the details manually.
- Manual configuration: Copy the Login URL, Logout URL, Entity ID, and Signing Certificate, which will be used during the configuration of Cisco Umbrella.
- Upload metadata file: Obtain the metadata file to be uploaded during the configuration of Cisco Umbrella in Identity360 by clicking Download from the Metadata field.
Integration Settings of SSO configuration for Cisco Umbrella.
Cisco Umbrella (service provider) configuration steps
- Log in to Cisco Umbrella with admin privileges.
- From the left menu, expand the Admin section, click Authentication > ENABLE SAML.
Portal view of Cisco Umbrella.
- Under the Select Umbrella SAML Provider step, select Other and click NEXT.
Steps to configure SAML SSO for Cisco Umbrella.
- Under the Cisco Umbrella Metadata step, click NEXT.
Metadata of Cisco Umbrella.
- For manual configuration, click the Manual Configuration radio button, and paste the Entity ID, Login URL, Logout URL, and Signing Certificate copied from step 6a of prerequisites in the Entity ID, Sign On URL, Logout URL, and X509 Certificate fields, respectively. Click NEXT.
Metadata upload configuration in Cisco Umbrella.
- For uploading metadata file, click the XML File Upload radio button, and upload the downloaded metadata file downloaded in step 6b of prerequisites.
- Click NEXT.
Manual configuration in Cisco Umbrella.
- Click TEST CONFIGURATION.
SSO configuration test in Cisco Umbrella.
- After the test completes, a success message will be displayed.
Identity360 (identity provider) configuration steps
- Switch to Identity360's application configuration page.
- Enter the Relay State parameter, if necessary.
Note: Relay State is an optional parameter used with a SAML message to remember where you were or to direct you to a specific page after logging in.
- Click Save.
Integration Settings of SSO configuration for Cisco Umbrella.
- To learn how to assign users or groups to one or more applications, refer to this help document.
Your users will now be able to sign in to Cisco Umbrella through the Identity360 portal.
Note: For Cisco Umbrella, both SP-initiated and IdP-initiated flows are supported.
Steps to enable MFA for Cisco Umbrella
Setting up MFA for Cisco Umbrella using Identity360 involves the following steps:
- Set up one or more authenticators for identity verification when users attempt to log in to Cisco Umbrella. Identity360 supports various authenticators, including Google Authenticator, Zoho OneAuth, and email-based verification codes. Click here for steps to set up the different authenticators.
- Integrate Cisco Umbrella with Identity360 by configuring SSO using the steps listed here.
- Now, activate MFA for Cisco Umbrella by following the steps mentioned here.
How does MFA for applications work in Identity360?