SAML2 with SCIM2 Integration GUIDE
CONFIGURING SAML2
PREREQUISITES
- A user with access to the Priverion Platform
- Your user must at least have IT Administrator role, or a Custom Role with IT Settings access
SUPPORTED FEATURES
- SP-initiated SSO
CONFIGURATION STEPS
- From the upper bar menu, click on the Settings icon button
- On the opened menu, select IT Settings
- Open the Identity & Access menu
- Select the SAML2/OAuth2 suboption
- Click on the Edit button in order to open the Authentication Configuration screen
- Make sure the SAML option is selected
- Select Custom or one of the prefilled options for Microsoft or Goole
- Make sure to configure with a comma separated list the Allowed domains for your case
- Use any of the options provided by the platform to configure the necessary credentials, you can either:
- Provide a metadata link on the Identity Provider Metadata URL and load the information automatically
- Manually write the Identity Provider Login URL & Identity Provider Logout URL and upload a valid Certificate file on the Identity Provider X 509 Certificate section
- Just write everything manually
- Define the Name ID format from the list according to your provider
- Configure the Group-Claims mapping according to your provider. Full Name, E-mail and Groups are mandatory
- OPTIONAL. Configure the options for Sign all messages & Encrypt Name ID if your provider supports it
- OPTIONAL. Activate SCIM2 support for Users & Groups provisioning if necessary, via the Enable SCIM2 option
CONFIGURING SCIM2
PREREQUISITES
- A user with access to the Priverion Platform
- Your user must at least have IT Administrator role, or a Custom Role with IT Settings access
- Authentication configuration set with SAML2
SUPPORTED FEATURES
- User operations
- Create
- Read
- Update
- Deactivate
- Group operations
- Create
- Read
- Update
- Delete
CONFIGURATION STEPS
- From the upper bar menu, click on the Settings icon button
- On the opened menu, select IT Settings
- Open the Identity & Access menu
- Select the SAML2/OAuth2 suboption
- Click on the Edit button in order to open the Authentication Configuration screen
- Activate the SCIM2 integration by enabling the option Enable SCIM2
- Navigate back to the Identity & Access
- Select the SCIM2 suboption menu. There you should find the necessary SCIM2 endpoints provided by the platform according to your Instance and Company
CONFIGURING AUTHORIZATION
PREREQUISITES
- A user with access to the Priverion Platform
- Your user must at least have IT Administrator role, or a Custom Role with IT Settings access
- Already configured Groups provisioning through SCIM2
- Synced Groups from your Identity Provider
CONFIGURATION STEPS
- From the upper bar menu, click on the Settings icon button
- On the opened menu, select IT Settings
- Open the Identity & Access menu
- Select the Role Mapping suboption
- Click on the Edit button
- Map provided Groups to any of the Priverion Platform Roles according to your requirements