Adding Microsoft Azure Active Directory as an IdP using SAML

This procedure explains how to integrate Forescout Cloud with an Microsoft Azure Active Directory as an IdP using the SAML protocol.

The following prerequisites must be set in your IdP configuration (consult your IdP vendor's documentation):

  • An active Azure subscription with access to Azure Active Directory (AAD).
  • Administrative rights to configure SSO settings in both Azure and the Forescout Cloud.

When configuring Microsoft AD as an IdP using SAML, complete the following tasks:

  1. Select the Identity Provider tab under Administration > Account Settings.
  2. Click + Add Identity Provider.
  3. Select SAML from the Identity Provider dropdown.
  4. Enter your choice for the name of this IdP integration in the NAME field.
  5. Enter the email domain for your SAML account in the EMAIL DOMAIN field.

    The configuration values for ISSUER URI, IDP SINGLE SIGN-ON URL and the Signature Certificate can be kept blank for now. These values can be filled in after creating a SAML Application in the Azure Portal later in this procedure.

  6. Click Save.
    The configured IdP appears on the main Identity Provider view and the actual Assertion Consumer URL is provided under Service Provider Information in Forescout Cloud.
  7. Click on the newly created SAML IDP, and copy the Audience URI and Assertion Consumer Service URL under Service Provider Information. These values will be needed when configuring the Microsoft Azure portal later in this procedure.
  8. Create a SAML application on the Microsoft Azure portal:
    1. In the Microsoft Azure portal, navigate to Microsoft Entra ID and select "Enterprise Application" as your choice of tenant.
    2. Select "Create your own application".
    3. Enter a Name for the application.
    4. Select "Integrate any other application you don't find in the gallery (Non-gallery)".
    5. Click Create.
    6. Select "Setup single sign on".
    7. Select "SAML" as the single sign on method.
  9. Configure the Basic SAML Configuration as follows:
    1. Identifier (Entity ID): Enter the "Audience URI" value noted in step 7.
    2. Reply URL (Assertion Consumer Service URL): Enter "Assertion Consumer Service URL" value noted in step 7.
    3. Sign on URL (optional): Enter the "Audience URI" value noted in step 7.
  10. Configure Attributes and Claims as follows:
    1. For the Unique User Identifier (Name ID), set the Source attribute to "user.mail" and configure the following additional attributes:
      • First name: Map this to the attribute that represents the user's first name (e.g., givenName).
      • Last name: Map this to the attribute that represents the user's last name (e.g., surname).
      • Email: Map this to the attribute that represents the user's email address (e.g., user.mail).
        Note: Name, Source, and Source Attribute values must be set in your Azure SAML configuration. The Namespace and Claim Condition attribute values are not needed.
  11. Configure SAML Certificates as follows:
    1. Download Certificate (Base 64)
    2. Download Certificate (Raw)
    Save both certificates as they will be needed later in this procedure.
  12. Configure Users and Groups as follows: Go to Manage > select users and groups > add user/group > Select > Assign to your Application.
  13. In Forescout Cloud, click on the IDP configuration you created at the beginning of this procedure and complete the following:
    1. Enter Microsoft Entra ID (Entity ID) copied from in the IDP ISSUER URI field in Azure.
    2. Enter the IDP SINGLE SIGN-ON URL value copied from the Login URL field in Azure.
    3. Upload the SAML signature certificate you downloaded from Azure earlier by clicking the Upload button in the IDP SIGNATURE CERTIFICATE field.
    4. Click Apply.
  14. The connection must be successful to enable the IdP configuration. Test it as follows:
    1. Copy the test URL.
    2. Open a new incognito tab and paste in the URL - the URL will redirect to your IdP login page; complete the login process there. If the login is successful you will be redirected to a page showing a successful test result.
    3. In Forescout Cloud, verify the results of the test posted on the main Identity Provider view under Account Settings. The IdP configuration can be enabled after confirmation of a successful test connection.

When the test confirms that the IdP has been successfully configured, it will appear in the list of configured IdPs with a TEST STATUS of SUCCESSFUL. You can then enable the IdP by clicking the Enabled check box.

With the Googe IdP activated, you can then log in to using single sign-on (SSO) using the following link: