Configuring SAML in AssetExplorer

Configuring SAML in AssetExplorer


Role Required: SDAdmin
 
Go to Admin > Organizational Details > SAML Single Sign-On.

In the configurations tab, you will find two sections: Service Provider Details and Configure Identity Provider Details.
 

Service Provider Details

Under the Service Provider Details section, you will find the following:
Field Name
Explanation
Entity ID

Use these details to configure AssetExplorer as a service provider in your IdP.
Assertion Consumer URL
Single Logout Service URL
SP Certificate
Click the file to download it. Upload this file in the IdP portal.
SP Metadata file
In some IdPs, uploading the metadata file is enough to configure AssetExplorer as a service provider.
 
Info
Changing the alias URL and the service from http to https will be reflected in the Assertion Consumer URL and Single Logout Service URL. You will have to reconfigure SAML authentication in both SP and IdP portals by regenerating the SP certificate. 

First, you must configure AssetExplorer as a Service Provider with your Identity Provider.

We have tested SAML 2.0 with ADFS 3.0, Okta, and OneLogin, Azure, and G Suite as the Identity Providers. Click the respective IdPs for configuration information. For ICAM, there are some additional configurations which can be checked here.

After configuring AssetExplorer as a service provider in your IdP domain, return to the SAML configuration page in AssetExplorer.
 

Configure Identity Provider Details

Under the Configure Identity Provider Details section,
  1. Enter the Login URL and Logout URL of the IdP.
  2. Select the Name ID Format based on your login preference.
  3. To log in using your username, select Transient or Persistent. Ensure that the format selected matches the configuration in your Identity Provider.
  4. If you wish to log in using your email address, select Email Address.
  5. If you wish to log in using the User Principal Name (UPN) configured in your Active Directory account, select Unspecified.
  6. Select the Algorithm from the drop-down. This algorithm should be the same as that configured in the IdP.
  7. Upload the IdP certificate by clicking the Choose File button.
  8. Click Save. The details of the certificate will be displayed to the right.
  9. Enable SAML authentication using the toggle button available on the top of the page.


  
The History tab lists all the activities carried out on the configuration page. You can view the activities related to a particular attribute using predefined filters as shown below.