Version Affected: All
Overview
This article covers additional configuration that may be needed to complete a Box (SP-Initiated) SAML integration, supplementing SecureAuth's official Box (SP-Initiated) Integration Guide. Box has changed its integration requirements over time, so some realms need these additional steps beyond the guide.
Configure Box (SP-Initiated) SAML Integration
- On the Post Authentication tab, set the SAML Consumer URL to Box's ACS URL — for example, https://sso.services.box.net/sp/ACS.saml2. Box does not support SP-initiated by POST on either side, so confirm this with a Box engineer if it comes up.
- The SP Start URL may also be required — for example, https://sso.services.box.net/sp/startSSO.ping?PartnerIdpId=https://example.com/secureauth19&TargetResource=#target_resource#.
- Configure the following SAML Attributes: Email, FirstName, and LastName.
These attribute names and formats must match what Box expects on their side — if the integration still fails after configuring them, confirm the expected values with Box support.
Special Considerations
Box's admin console for SAML configuration may not be user-configurable without a Box engineer on the call. If the integration is still not working after completing the steps above, contact Box support to confirm the settings on their side.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.