How To: Integrate Cisco Umbrella with SecureAuth Connect (SAML)

Follow
    Applies to:
  • Connect
Deployment model:
  • Cloud
  • Version Affected: SecureAuth Connect

     

    Overview

    This article explains how to integrate Cisco Umbrella with SecureAuth Connect using SAML, so users can sign in to Cisco Umbrella through SecureAuth Connect.

    There is more than one way to do this:

    • Configure the SecureAuth Connect side as a SAML client for Cisco Umbrella
    • Configure the Cisco Umbrella side to use SecureAuth Connect as its SAML identity provider

    In this article

     

    Method 1: SecureAuth Connect Configuration

    Before you begin, you need a SecureAuth Connect Workforce workspace with administrative privileges, configured with the same user store defined in your Cisco Umbrella configuration, and a Cisco Umbrella account with administrative privileges.

    • Log in to your SecureAuth Connect Workforce workspace with an admin account.
    • In your workspace, select Applications > Clients > Create client.

    SecureAuth Connect Applications menu with Clients and Create client options.

    • Enter a name, optionally provide your Umbrella login URL in the Application URL field (used if you want it to appear in the user portal after login), select SAML Service Provider, and click Create.

    Create client form with SAML Service Provider selected.

    • Download the SAML Metadata.

    Client configuration page with the SAML Metadata download option.

    • Scroll down and enable Override SAML Attributes.

    Override SAML Attributes toggle enabled.

    • Go to the Attributes tab, choose mail from the predefined attribute list, and click Save to apply the changes.

    Attributes tab with the mail attribute selected.

    • On the SAML tab, select Manual and set the following configurations:
      • Entity ID: the Entity ID for Cisco Umbrella. By default this is https://login.umbrella.com/sso.
      • Assertion Consumer Service (ACS) URL: the SAML consumer URL provided for Cisco Umbrella, for example https://login.umbrella.com/sso. You can also download the Cisco Umbrella metadata from the Cisco Umbrella configuration steps below, then select XML instead of Manual and upload the Umbrella metadata file.
      • Enable Override Subject NameID, set Name ID Format to urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress, and set Name ID Value to mail.
    • Click Save.

    SAML tab with Override Subject NameID enabled and Name ID Format and Value configured.


     

    Method 2: Cisco Umbrella Configuration

    With the SecureAuth Connect client created and its SAML metadata ready, configure Cisco Umbrella to use it as the SAML identity provider.

    1. Log in to Cisco Umbrella with an administrative account.
    2. On the left side, click Admin > Authentication.
    3. On the SAML Dashboard User Configuration page, click ENABLE SAML.
    4. Select the Other option, then click NEXT.
    5. Download the Cisco Umbrella SAML metadata, or copy the metadata from the text box, and click NEXT. Make sure the data matches what you specified in the SecureAuth Connect configuration.
    6. Select the XML File Upload option, upload the SecureAuth Connect metadata, then click NEXT.
    7. To verify your configuration and SAML metadata, click TEST CONFIGURATION.
    8. A new window displays a QR code. Scan the QR code; you should then see a success message.
    9. Click NEXT.
    10. On the Save and Notify page, select both check boxes and click SAVE AND NOTIFY USERS.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.