Configuring SAML Single Sign-On for Active Directory Users using ADSelfService Plus4 minutes to read
ManageEngine PAM360 integrates seamlessly with ADSelfService Plus (ADSSP), enabling organizations to configure ADSSP as an Identity Provider (IdP) for SAML Single Sign-On (SSO). If you are currently using ADSSP to manage your AD users, this configuration will streamline the authentication process by leveraging your existing infrastructure. By configuring PAM360 as a Service Provider (SP) and ADSSP as an IdP, users can log into PAM360 with their AD credentials without needing to maintain a separate set of credentials for PAM360. Setting up ADSSP as the IdP enables SSO capabilities, allowing AD users to access PAM360 seamlessly without re-entering their credentials. This help documentation covers the following topics in detail: 1. Prerequisites
2. Configuring PAM360 as an SP in ADSSPFollow these steps to configure PAM360 as an SP in the ADSSP console:
3. Configuring ADSSP as an IdP in PAM360After configuring PAM360 as an SP in the ADSSP console, you must configure ADSSP as an IdP in PAM360 to establish it as a trusted entity. Access the PAM360 browser window and proceed with IdP configuration starting from Step 2 - Configure Identity Provider Details. Explore this link for the detailed IdP configuration steps. Based on the provided steps, configure ADSSP as an IdP and configure the SAML properties on the PAM360 interface. Note: While configuring the SAML Properties during IdP configuration, select the Algorithm as SHA 1, Name ID Format as Unspecified, and the Protocol Binding as HTTP Post under Step 2 - Configure Identity Provider Details. | |