BeyondTrust Privileged Remote Access- SAML Relying Party Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as Relying Party to BeyondTrust Privileged Remote Access.Procedure
- Sign in to RSA Cloud Administration Console.
- Navigate to the Authentication Clients menu and click Relying Parties.
- On the Relying Party Catalog page, click Add a Relying Party and click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- On the Authentication page, choose SecurID manages all authentication.
- Select a Primary Authentication Method and Access Policy as required and click Next Step.
- For providing Service Provider details:
- Click Import Metadata and click Choose File.
- Select the file that is downloaded from the Service Provider.
See the Configure BeyondTrust Privileged Remote Access section to download the metadata.
- Review the ACS URL and Service Provider Entity ID values that are auto-filled.
- In the SAML Response Protection section, choose IdP signs entire SAML response.
- Download the certificate by clicking Download Certificate.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: persistent and Property: mail.
- Add the Attributes as shown in the following figure under the Statement Attributes section.
- Click Save and Finish.
- On the My Relying Parties page, click the Edit drop-down icon and select the Metadata option to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure BeyondTrust Privileged Remote Access
Perform these steps to configure BeyondTrust Privileged Remote Access.Procedure
- Sign in to BeyondTrust Privileged Remote Access as administrator.
- Navigate to Users & Security > SECURITY PROVIDERS.
- Click ADD and select SAML2.
- Provide a Name and select the Enabled checkbox.
- Provide the following information.
- Entity ID: Obtain from the metadata file downloaded from RSA.
- Single Sign-On Service URL: Obtain from the metadata file downloaded from RSA.
Click UPLOAD CERTIFICATE and upload the certficate that was downloaded from RSA.
- Click DOWNLOAD SERVICE PROVIDER METADATA.
- Under Authorization Settings, select a desired group policy and click SAVE.
Notes
Make sure that the Group policy is configured in BeyondTrust application.RSA users need to be part of a Group Membership and its value should be same as BeyondTrust Default Group Policy as shown in the preceding figure.
The configuration is complete.
Return to BeyondTrust Privileged Remote Access - RSA Ready Implementation Guide.
Related Articles
BeyondTrust Privileged Remote Access - SAML My Page SSO Configuration - RSA Ready Implementation Guide 17Number of Views BeyondTrust Privileged Remote Access - RSA Ready Implementation Guide 66Number of Views BeyondTrust Password Safe - RADIUS Configuration in Authentication Manager - RSA Ready Implementation Guide 4Number of Views BeyondTrust Password Safe - SAML My Page SSO Configuration – RSA Ready Implementation Guide 5Number of Views BeyondTrust Password Safe – RSA Ready Implementation Guide 64Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to Download OTP Token Seed Files from myRSA Installing a new license on RSA Authentication Manager RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?