Configuring SAML Authentication

To implement Azure Active Directory using SAML, you must first configure SAML in Microsoft Azure Portal and then configure SAML Authentication in Logpoint.

Configuring SAML Authentication in Microsoft Azure Portal

To implement Azure Active Directory using SAML, first you need to:

  1. Add Azure AD SAML Toolkit

  2. Creating User Account

  3. Assign the User Account to an Enterprise Application

  4. Enable SAML

in the Microsoft Azure Portal and then configure SAML Authentication in Logpoint .

Adding Azure AD SAML Toolkit

  1. Go to the Microsoft Azure Portal and log in with your credentials.

  2. Go to Azure Active Directory from the navigation bar and click Enterprise applications.

  3. Click All applications and + New application.

  4. Search and click Azure AD SAML Toolkit.

  5. Click Create.

_images/samlap1.png

Adding Azure AD SAML Toolkit

Creating User Account

  1. Go to Azure Active Directory from the navigation bar of Microsoft Azure Portal and click Users.

  2. Click the + New user drop-down and click Create a new user.

  3. Enter the users information and click Review + create.

  4. Click Create.

_images/samlap2.png

Creating a New User

Assigning the User Account to an Enterprise Application

  1. Go to Azure Active Directory from the navigation bar of Microsoft Azure Portal and click Enterprise applications.

  2. Click the previously added Azure AD SAML Toolkit.

  3. Go to Users and groups from the navigation bar and click + Add user/group.

_images/samlap3.png

Adding User/Group

  1. Click None selected under Users and groups.

  2. Search for the user or group to assign to the application and select it.

  3. Click Select and then Assign.

Enabling SAML

  1. Go to Azure Active Directory from the navigation bar of Microsoft Azure Portal and click Enterprise applications.

  2. Click the previously added Azure AD SAML Toolkit.

  3. Go to Single sign-on from the navigation bar and click SAML.

_images/samlap4.png

Enabling SAML

  1. Click the edit icon of Basic SAML Configuration.

  2. Click Add reply URL and enter https://samltoolkit.azurewebsites.net/SAML/Consume.

  3. In Sign on URL, enter https://samltoolkit.azurewebsites.net/.

  4. Click Save.

_images/samlap6.png

Adding URL

  1. Note down the value of Identifier (Entity ID) of Basic SAML Configuration. You must enter it as Issuer (EntityID) while configuring SAML Authentication in Logpoint.

  2. Search and Download the Certificate (Base64) of SAML Signing Certificate. You must enter it as X.509 Certificate while configuring SAML Authentication in Logpoint.

  3. Note down the Login URL and Azure AD Identifier of Set up Azure AD SAML Toolkit. You must enter Login URL as SSO EndPoint URL and Azure AD Identifier as EntityID while configuring SAML Authentication in Logpoint.

Configuring SAML Authentication in Logpoint

The time zones of the IdP server and Logpoint must be identical.

  1. Go to Settings >> System Settings from the navigation bar and click Plugins.

  2. Find SAML Authentication and click Manage.

_images/saml_manage.png

Manage SAML Authentication

  1. Click ADD SERVER.

_images/saml-add-server.png

Add SAML Server

  1. Enter a unique Server Name.

  2. In Issuer (EntityID), enter the Logpoint’s IP address. You must add these Issuer (EntityID) and ACS (Consumer) URL in your IdP server. For Shibboleth, you must download the Logpoint metadata file and upload it in its server.

    SAML Authentication generates the ACS (Consumer) URL automatically.

  3. Enter the EntityID. You can find it in your IdP metadata file as entity ID.

  4. Enter the SSO EndPoint URL. You can find it in your IdP metadata file as Location in SingleSignOnService. The SingleSignOnService must be HTTP-POST.

  5. Enter the X.509 Certificate. You can find it in your IdP metadata file as the signing certificate. For Shibboleth, you can find it as the FrontChannel signing certificate.

  6. In Response Username Field, enter the field to extract the username from the SAML response.

  7. In Response Role Field, enter the field to extract the role from the SAML response.

  8. Click Save.

_images/saml_server-added.png

Adding an IdP Server

  1. Click Yes to make SAML authentication as the default authentication. Otherwise, click No.

_images/saml_default-box.png

Select Authentication

Once you add an IdP server, Role Mapping is added and Add Server is removed in SAML Authentication management.

_images/saml_rolemapping.png

SAML Authentication Management

Configuring Default Settings

  1. Go to Settings >> System Settings from the navigation bar and click Plugins.

  2. Find SAML Authentication and click Manage.

  3. Click Default Settings.

_images/saml_management_panel1.png

SAML Authentication Management

  1. Select a Logpoint user group as the Default Role. SAML Authentication assigns the user group to the SAML Authentication users whose role attribute are not returned by the IdP server.

  2. Click Save.

_images/adfs_default-settings.png

Default Settings

Downloading Logpoint Metadata

  1. Go to Settings >> System Settings from the navigation bar and click Plugins.

  2. Find SAML Authentication and click Manage.

  3. Click the Download icon from Actions.

_images/saml_metadata.png

Downloading Logpoint Metadata

Mapping Roles

You can map a SAML role to a Logpoint user group to grant access permission in Logpoint. A SAML role can be mapped to a single Logpoint user group only. This is mandatory.

To map a SAML role to a Logpoint user group:

  1. Go to Settings >> System Settings from the navigation bar and click Plugins.

  2. Find SAML Authentication and click Manage.

  3. Click Roles Mapping.

_images/saml_role-mapping.png

Role Mapping

  1. Enter a SAML Role.

  2. Select a LogPoint User Group for the provided SAML role.

_images/saml_role-map-panel.png

SAML Role Mapping

  1. Click Add.

    You can view all the mapped SAML roles and Logpoint user groups in Role Map Strategies. You can either edit or delete them from Actions.

_images/saml_role-map-added.png

SAML Roles

  1. Click Submit.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support