Using SAML Single Sign-On (SSO), administrators can securely sign in to the SendSafely MPA using your organization’s identity provider (IdP).
SAML SSO setup for the MPA currently requires coordination between your organization and the SendSafely support team. Before beginning the configuration, contact support@sendsafely.com to initiate the setup process.
Step 1: Configure SendSafely in Your Identity Provider
Use the following values for configuring the MPA as a SAML application in your identity provider:
- Assertion Consumer Service (ACS) URL:
-
Service Provider (SP) Entity ID:
- urn:amazon:cognito:sp:us-east-1_nMDUjkjUC
Use these values when creating or configuring the SendSafely MPA application in your identity provider.
Step 2: Provide Your SAML Configuration to SendSafely
After configuring the application in your identity provider, provide the following information to SendSafely:
- SAML metadata XML file — The metadata/manifest XML file generated by your identity provider.
- SAML provider name — A name that can be used to identify your SAML configuration.
- Email attribute name — The SAML attribute or claim containing the administrator’s email address.
- Administrator email addresses — The email addresses of each administrator who should be permitted to access the MPA using SSO.
- Allowed IP addresses - REQUIRED. The IP addresses authorized to connect to the MPA. These can be individual addresses or a range specified using CIDR notation. Providing allowed IP addresses is a requirement for MPA use.
SendSafely will use this information to complete the SAML configuration.
Step 3: Administrator Account Provisioning
The MPA does not currently support automatic user provisioning through SAML.
Before an administrator can sign in using SSO, an MPA user account with a matching email address must be created by SendSafely. For this reason, include the email address of each administrator who requires MPA access when requesting SAML configuration.
If additional administrators require access in the future, contact SendSafely to have their MPA accounts provisioned before they attempt to sign in using SSO.
Step 4: Complete and Verify the Configuration
After receiving your SAML configuration and administrator information, SendSafely will complete the required configuration on the SendSafely side.
Once configuration is complete, SendSafely will notify you that SAML SSO is ready for testing. An administrator can then sign in using your organization’s identity provider to verify that authentication is working correctly.
Comments
0 comments
Article is closed for comments.