Configuring OneLogin as Identity Provider
Role Required: SDAdmin
- Log in your OneLogin domain and click Applications under the Applications tab.
- In the displayed page, click Add App.
- Search for SAML from the search box and select SAML Test Connector (Advanced) from the search results.
- Provide a Name and upload a Logo for your application.
- Click Save.
- Go to the Configurations tab and enter the details as given below.
Field Name
| Description
|
ACS (Consumer) URL Validator
| Assertion Consumer URL in AssetExplorer
|
ACS (Consumer) URL
| Assertion Consumer URL in AssetExplorer
|
Single Logout URL
| Single Logout Service URL in AssetExplorer
|
Audience (Entity ID)
| Entity ID in AssetExplorer
|

- Select the required SAML nameID format from the drop-down. AssetExplorer supports the following formats:
- Email: Choose this if you want to login using the email address configured in AssetExplorer.
- Transient/Persistent: Choose this format if you want to login using the login name configured in AssetExplorer.
- Unspecified: Choose this if you want to login using the User Principal Name of your Active Directory account imported into AssetExplorer.
- Click Save.
- Open the Parameters tab.
- Click NameID value. In the displayed drop-down, choose the required value for the NameID format selected in the previous screen using the following pointers:
- For email format, select Email as the value.
- For Persistent/Transient formats, select an option that returns the value in the format <DOMAIN\username>.
- Alternatively, select Macro to configure a custom option to achieve the same. The syntax can be found here.
- For Unspecified format, select userPrincipalName as the value.

- Under the SSO tab, you will find the IdP details to be entered in the AssetExplorer application.
- Enter the details as given below.
AssetExplorer Attribute
| OneLogin Attribute
|
Login URL
| SAML 2.0 Endpoint
|
Logout URL
| SLO Endpoint
|
- To download the certificate, click the View Details option under X.509 Certificate.
- Choose the certificate format as X.509 PEM/X.509 DER and click Download.
- You can assign the application to various users under the Users tab.
You have now configured AssetExplorer as a service provider in OneLogin.
Go to the SAML configuration page in AssetExplorer and provide the IdP details to complete the integration.