Configuring Single Sign-On (SSO) using SAML 2.0 for Okta11 minutes to read
Note: The procedure outlined in this document applies only till PAM360 builds 7301. For builds 7400 and above, please refer to this help document. ManageEngine PAM360 supports SAML 2.0, enabling integration with Federated Identity Management Solutions for Single Sign-On (SSO). PAM360 acts as the Service Provider (SP) and integrates with Identity Providers (IdP) using SAML 2.0. The integration process involves exchanging SP details with IdP and vice versa to establish trust between the SP and IdP and facilitate seamless authentication. Once integrated, users can log in to the IdP and automatically gain access to PAM360 from the IdP's GUI without needing to re-enter their credentials, streamlining the authentication process. PAM360 offers out-of-the-box integration with Okta. ManageEngine PAM360 supports SAML 2.0, enabling integration with Federated Identity Management Solutions for Single Sign-On (SSO). PAM360 acts as the Service Provider (SP) and integrates with Identity Providers (IdP) using SAML 2.0. The integration process involves exchanging SP details with IdP and vice versa to establish trust between the SP and IdP and facilitate seamless authentication. Once integrated, users can log in to the IdP and automatically gain access to PAM360 from the IdP's GUI without needing to re-enter their credentials, streamlining the authentication process. PAM360 offers out-of-the-box integration with Okta. Note: PAM360 also supports configuring SAML SSO for the Secondary server, allowing users to log in to PAM360 via the Secondary server when the Primary server is down, ensuring continuous access and minimal disruption. This document covers the following topics in detail:
Follow these steps to seamlessly integrate PAM360 with Okta, enabling a smooth and secure SSO and SLO experience. 1. PrerequisitesTo configure PAM360 as an SP on the Okta dashboard, you need the SP details displayed on the Configuration For Single Sign-On Using SAML page under the Service Provider Details section. These details are necessary for setting up PAM360 as an SP on the Okta dashboard, ensuring a seamless integration between PAM360 and Okta. Explore this link for the detailed steps to obtain the required SP details for configuring PAM360 as an SP on the Okta dashboard. 2. Adding PAM360 as an Application on the Okta DashboardFollow these steps to add PAM360 as an application on the Okta dashboard and configure the SAML settings.
On the Create SAML Integration page, you should complete the following configurations: General Settings and Configure SAML. 2.1 General SettingsOn the Create SAML Integration page, under General Settings, you should provide essential information about the application you are adding. Follow these steps to complete this section:
2.2 Configure SAMLOn the Configure SAML window, under SAML Settings, enter the following details.
Note: For SAML SSO authentication, the Assertion Consumer Service (ACS) URL is the hostname of the PAM360 server by default. Follow these steps to update the ACS URL: After configuring the SAML properties, specify the Attribute Statements. The attribute statement is a crucial part of the SAML assertions that provides information about the authenticated user. PAM360 identifies the user by cross-referencing the attribute within the attribute statement with its username before granting access to the user. As the usernames in Okta and PAM360 could be different, you must specify the format. There are two possible scenarios:
After configuring the required parameters, click the Preview the SAML Assertion option to review a sample of the SAML assertion that will be sent by the IdP to PAM360. Then, click Next to proceed to the next step. Complete the feedback questionnaire and click Finish to finalize the SP configuration and SAML parameters on the Okta Dashboard. 3. Assigning PAM360 Application to UsersAfter setting up the newly added application integration (PAM360), you must assign it to the users in your Okta directory.
Notes:
4. Downloading Okta IdP Metadata FileFollow these steps to download the IdP details as a metadata.xml file after configuring PAM360 as an SP.
| |