Version Affected: SecureAuth Connect
Overview
This article explains how to integrate Cisco Umbrella with SecureAuth Connect using SAML, so users can sign in to Cisco Umbrella through SecureAuth Connect.
There is more than one way to do this:
- Configure the SecureAuth Connect side as a SAML client for Cisco Umbrella
- Configure the Cisco Umbrella side to use SecureAuth Connect as its SAML identity provider
In this article
Method 1: SecureAuth Connect Configuration
Before you begin, you need a SecureAuth Connect Workforce workspace with administrative privileges, configured with the same user store defined in your Cisco Umbrella configuration, and a Cisco Umbrella account with administrative privileges.
- Log in to your SecureAuth Connect Workforce workspace with an admin account.
- In your workspace, select Applications > Clients > Create client.
- Enter a name, optionally provide your Umbrella login URL in the Application URL field (used if you want it to appear in the user portal after login), select SAML Service Provider, and click Create.
- Download the SAML Metadata.
- Scroll down and enable Override SAML Attributes.
- Go to the Attributes tab, choose mail from the predefined attribute list, and click Save to apply the changes.
- On the SAML tab, select Manual and set the following configurations:
- Entity ID: the Entity ID for Cisco Umbrella. By default this is https://login.umbrella.com/sso.
- Assertion Consumer Service (ACS) URL: the SAML consumer URL provided for Cisco Umbrella, for example https://login.umbrella.com/sso. You can also download the Cisco Umbrella metadata from the Cisco Umbrella configuration steps below, then select XML instead of Manual and upload the Umbrella metadata file.
- Enable Override Subject NameID, set Name ID Format to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, and set Name ID Value to mail.
- Click Save.
Method 2: Cisco Umbrella Configuration
With the SecureAuth Connect client created and its SAML metadata ready, configure Cisco Umbrella to use it as the SAML identity provider.
- Log in to Cisco Umbrella with an administrative account.
- On the left side, click Admin > Authentication.
- On the SAML Dashboard User Configuration page, click ENABLE SAML.
- Select the Other option, then click NEXT.
- Download the Cisco Umbrella SAML metadata, or copy the metadata from the text box, and click NEXT. Make sure the data matches what you specified in the SecureAuth Connect configuration.
- Select the XML File Upload option, upload the SecureAuth Connect metadata, then click NEXT.
- To verify your configuration and SAML metadata, click TEST CONFIGURATION.
- A new window displays a QR code. Scan the QR code; you should then see a success message.
- Click NEXT.
- On the Save and Notify page, select both check boxes and click SAVE AND NOTIFY USERS.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.