Adding an Identity Provider using SAML
This procedure explains how to integrate Forescout Cloud with an IdP using the SAML protocol.
The following prerequisites must be set in your IdP configuration (consult your IdP vendor's documentation):
- The Entity ID
- The Assertion Consumer URL
- NAME
-
EMAIL DOMAIN
-
IDP ISSUER URI
-
IDP SINGLE SIGN-ON URL
-
IDP SIGNATURE CERTIFICATE
-
IDP ISSUER URI
To add an identity provider using SAML to Forescout, complete the following procedure:
- Select the Identity Provider tab under Administration > Account Settings.
- Click + Add Identity Provider.
- Select SAML from the Identity Provider dropdown.
- Enter your choice for the name of this IdP integration in the NAME field.
- Enter the email domain for your SAML account in the EMAIL DOMAIN field.
- Enter the following configuration information:
- Enter IdP issuer URI in the IDP ISSUER URI field.
- Enter the IdP single sign-on URL in the IDP SINGLE SIGN-ON URL field.
- Upload your SAML signature by clicking the Upload button in the IDP SIGNATURE CERTIFICATE field.
Note: If you do not yet have the above configuration values, you can leave the fields blank for now. - Click Save.
The configured IdP appears on the main Identity Provider view and the Assertion Consumer URL and Audience URI (Entity ID) is provided under Service Provider Information.
- Click the newly created SAML IdP provider and copy the Assertion Consumer Service URL and Audience URI that appears under Service Provider Information.
- If you left values blank in Step 6, enter them now:
- Enter IdP issuer URI in the IDP ISSUER URI field.
- Enter the IdP single sign-on URL in the IDP SINGLE SIGN-ON URL field.
- Upload your SAML signature by clicking the Upload button in the IDP SIGNATURE CERTIFICATE field.
- The connection must be successful to enable the IdP configuration. Test it as
follows:
- Copy the test URL.
- Open a new incognito tab and paste in the URL - the URL will redirect to your IdP login page; complete the login process there. If the login is successful you will be redirected to a page showing a successful test result.
- In Forescout Cloud, verify the results of the test posted on the main Identity Provider view under Account Settings. The IdP configuration can be enabled after confirmation of a successful test connection.
When the test confirms that the IdP has been successfully configured, it will appear in the list of configured IdPs with a TEST STATUS of SUCCESSFUL. You can then enable the IdP by clicking the Enabled check box.
minute read