OneLogin - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.Procedure
- Enable My Page SSO by accessing the RSA Cloud Administration Console > Access > My Page > Single Sign-On (SSO). Ensure it is enabled and protected using two-factor authentication - Password and Access Policy.
- On the Applications > Application Catalog page, search for OneLogin and click Add to add the connection.
- On the Basic Information page, enter a name for the configuration in the Name field and click Next Step.
- On the Connection Profile page, click the IdP-initiated option.
- Provide the Service Provider details in the following format:
- ACS URL: https://<your-subdomain>.onelogin.com/access/idp.
- Service Provider Entity ID: <OneLogin Entity ID>
Refer to the Configure OneLogin section to obtain ACS URL and Entity ID.
- In the SAML Response Protection section, choose IdP signs assertion within response.
- Download the certificate by clicking Download Certificate.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: Auto Detect and Property: Auto Detect.
- Under the Statement Attributes section, add the attributes as shown in the following figure.
- Click Next Step.
- Choose your desired Access Policy for this application and click Next Step > Save and Finish.
- On the My Applications page, click the Edit drop-down icon and select Export Metadata to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure OneLogin
Perform these steps to configure OneLogin.Procedure
- Log on to OneLogin with administrator credentials.
- Click Administration.
- Click Authentication and select Trusted IdPs.
- Click New Trust.
- Provide a name for the IdP and click the green tick icon.
- Under the Configurations section, provide the following details:
- Issuer – The EntityID value that can be obtained from the metadata file downloaded from RSA.
- Email Domains – Provide one or more domains, separated by commas. Authentication will be initiated for users who enter any email address with one of these domains.
- Select the Sign users into OneLogin checkbox.
- Under the SAML Configurations section, provide the following:
- IdP Login URL – The SingleSignOnService value that can be obtained from the metadata file downloaded from RSA.
- SP Entity ID – Use this value while configuring RSA.
- Obtain the your-subdomain value from the SP Entity ID that is used to construct the ACS URL. The your-subdomain value is found in https://<your-subdomain>. onelogin.com.
- To construct the ACS URL, copy the your-subdomain value and paste it into the following URL: https://<your-subdomain>. onelogin.com/access/idp
- Under the Trusted IdP Certificate section, copy and paste the certificate downloaded from RSA.
- Scroll up, select the Enable Trusted IDP checkbox, and click Save.
The configuration is complete.
Return to OneLogin - RSA Ready Implementation Guide.
Related Articles
Delinea - SAML My Page SSO Configuration - RSA Ready Implementation Guide 14Number of Views Palo Alto NGFW Global Protect - SAML My Page SSO Configuration - RSA Ready Implementation Guide 43Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Microsoft Office 365 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 119Number of Views
Trending Articles
RSA Authentication Manager Patch Updates RSA Authentication Manager 8.9 Release Notes (January 2026) Unification is failing at step 8 on "AVUSER.ROLE_MANAGEMENT_PKG", line 2469 in RSA Governance & Lifecycle How to Update the Root (Server) and Client Certificates in RSA Identity Governance & Lifecycle RSA Announces the Release of RSA MFA Agent 2.5 for Microsoft Windows
Don't see what you're looking for?