RSA Governance and Lifecycle - RSA Ready Implementation Guide
a year ago
Originally Published: 2022-04-21

Certified: January 22th, 2025 

 

Solution Summary

This section describes the ways in which RSA Governance and Lifecycle can integrate with RSA SecurID Access. Use this information to determine which use case and integration type your deployment will employ.

 

Integration Types

My Page SSO provides Single-Sign-On (SSO) to G&L users leveraging RSA self-service portal My Page. When integrated, users must authenticate with RSA to sign in Governance and Lifecycle. Both SP-initiated SSO and IdP-initiated SSO are supported. Modern Cloud-hosted SSO with My Page replaces the existing SAML SSO support with the IDR. Existing SSO integrations using IDR My Applications continue to be supported and will be listed in this document as applicable.

Note: RSA will continue to maintain existing SAML SSO integrations using IDR My Applications. At a to-be-determined future date, RSA will announce the end-of-life (EOL) date for the SAML SSO support with the IDR. For more information Available Now: My Page SSO Enhancements - RSA Community - 680715. 

 

Relying Party integration allows Governance and Lifecycle users’ web browsers to be automatically redirected to RSA Cloud Authentication Service for authentication. With Relying Party integration, Cloud Authentication Service can manage only additional authentication or both primary authentication (for example, user ID and password) and additional authentication.

Internal Applications and/or Identity Management System - When integrated, users must authenticate with RSA ID plus to create sessions to internal applications and/or identity management system using adapters. 

Bridge between RSA SecurID Access SAML IdP and Partner Service Providers - When integrated, users must authenticate with RSA ID plus to create sessions to partner Service Providers using authentication policy contracts. 

 

Supported Features

This section shows all of the supported features by integration type and by RSA SecurID Access component. Use this information to determine which integration type and which RSA SecurID Access component your deployment will use. The next section contains the steps to integrate RSA SecurID Access with RSA Governance and Lifecycle for each integration type.

 

RSA Governance and Lifecycle Integration with RSA Cloud Authentication Service

Authentication Methods

Authentication API

RADIUS

My Page SSO

Relying Party

SSO Agent

RSA SecurID--
LDAP Password--
Authenticate Approve--
Authenticate Tokencode--
Device Biometrics--
SMS Tokencode--
Voice Tokencode--
FIDO Tokenn/an/a
Identity Assurance--

 

RSA Governance and Lifecycle Integration with RSA Authentication Manager

Authentication MethodsAuthentication APIRADIUSAuthentication Agent
RSA SecurID---
On-Demand Authentication---
Risk-Based Authenticationn/a--

 

Supported
-Not supported
n/tNot yet tested or documented, but may be possible.

Configuration Summary

The following links provide instructions on how to integrate RSA Governance and Lifecycle with RSA SecurID Access.

This document is not intended to suggest optimum installations or configurations. It assumes the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products in order to install the required components. All RSA SecurID Access and RSA Governance and Lifecycle components must be installed and working prior to the integration.

 

Integration Configuration

 

Certification Details

Date of testing: January 22th, 2025 

RSA Cloud Authentication Service

RSA Governance and Lifecycle 12.2

 

Known Issues

No known issues.