This article describes how to integrate RSA with idGenius using SAML Relying Party.
Choose this mode over My Page SSO when:
- idGenius must not appear as a tile on RSA My Page (for example, because the user population should never see RSA self-service).
- The integration is SP-initiated only, and the deployment does not want the additional Application catalog metadata maintained.
- Federation is being driven by an upstream organization-level SAML policy rather than a per-application policy.
Functionally, the resulting SAML trust is equivalent to the My Page SSO setup; the difference is the RSA object where the trust lives and the lack of a My Page tile.
Configure RSA Cloud Access Service
Perform these steps to configure RSA Cloud Access Service (CAS) as a SAML Relying Party for idGenius.
Procedure
- Sign in to the RSA Cloud Administration Console as a super admin.
- Click Authentication Clients > Relying Parties. The list of configured Relying Parties is displayed.
- Click Add a Relying Party.
- On the Relying Party Catalog page, click Add for SAML.
- Populate the form with the following values on the respective pages. Click Next to navigate to the next page.
Field Value/Description Name A descriptive name for the relying party (for example, idGenius-<environment>). Description Optional internal note. Access Policy Bind the same RSA Access Policy that should gate this federation (factor mix, assurance level, step-up rules). Initiate SAML Workflow SP-initiated. Connection URL https://<idgenius-tenant>.idgenius.io Assertion Consumer Service (ACS) URL https://<idgenius-api-host>.idgenius.io/api/auth/saml/acs (Index 0, default). SP Entity ID https://<idgenius-tenant>.idgenius.io/saml Identity Provider URL (issued by RSA) https://<rsa-tenant>.auth.securid.com/sso/saml/<rp-uuid>. Copy this into idGenius as both IdP Entity ID and IdP SSO URL. SAML Response Protection IdP signs assertion within response (default). Encrypt Assertion Off — idGenius requires signing only.
Notes
- Relying Parties do not get a My Page tile. Users will only ever reach idGenius via SP-initiated SAML (typing the URL, clicking a corporate bookmark, or following a deep-link).
- Capture the IdP signing certificate from the Relying Party's Message Protection block and paste it into the idGenius SAML provider; the certificate is tenant-default unless overridden.
- Click Save and Finish.
- Click Publish Changes after saving so the Relying Party becomes live.
Configure idGenius
Perform these steps to configure idGenius.
Procedure
- Sign in to idGenius as a tenant administrator at https://<idgenius-tenant>.idgenius.io. Until SAML is enabled tenant-wide, administrators authenticate with email + password + email OTP.
Figure 1. idGenius login — the Sign in with SSO option is the entry point users will follow once the SAML provider is enabled.
- In the left pane, click Settings > Administration > Authentication. In the SSO Providers pane, click the SAML Providers tab.
Figure 2. Settings > Administration > Authentication tab.
- Click Add SAML Provider to open the configuration dialog (or click the pencil icon on an existing row to edit it).
Figure 3. SAML Providers list — Add SAML Provider opens the configuration dialog.
- Populate the dialog with the values captured from the RSA side.
Figure 4. Edit SAML Configuration — Provider identity, email domains and Identity Provider Configuration.
Field Value/Description Provider Name Unique slug (lowercase, no spaces) used in URLs and audit logs — for example, rsa-securid-saml. Display Name User-friendly label shown next to the Sign in with SSO button — for example, RSA SecurID SAML. Email Domains Comma-separated list of email domains that should auto-discover this provider. When a user types an email in one of these domains on the idGenius login page, idGenius redirects to RSA automatically. Example: anomalix.com,idgenius.io. IdP Entity ID Paste the Identity Provider URL captured from RSA: https://<rsa-tenant>.auth.securid.com/sso/saml/<app-uuid>. IdP SSO URL The same value — RSA uses one endpoint for both Issuer and SingleSignOnService. IdP SLO URL Leave blank unless an SLO endpoint is configured on the RSA side; idGenius will fall back to a local logout if SLO is unavailable. IdP Certificate (PEM) Paste the IdP signing certificate downloaded from the RSA Message Protection section. Existing certificates are encrypted at rest and cannot be displayed; enter a new value only when rotating. IdP Metadata XML Optional — if RSA's metadata XML is uploaded here, idGenius will use it as the authoritative IdP descriptor and the individual fields above are kept for human reference only. SP Entity ID * https://<idgenius-tenant>.idgenius.io/saml — must match the SP Entity ID configured on the RSA application. ACS URL * https://<idgenius-api-host>.idgenius.io/api/auth/saml/acs — must match the ACS URL configured on the RSA application. SP Metadata (read-only) Public URL idGenius exposes for direct import into the IdP: https://<idgenius-api-host>.idgenius.io/api/auth/saml/metadata/<provider-name>. Use the copy icon to retrieve it. - In the Advanced Options section, review the protocol-level details.
Figure 5. Edit SAML Configuration — Advanced Options (SSO Binding, NameID Format, Attribute Mapping JSON).
Field Value/Description SSO Binding HTTP-Redirect (default). RSA's SAML 2 Generic Direct SP endpoint supports both HTTP-Redirect and HTTP-POST; HTTP-Redirect is the recommended default. NameID Format Email Address (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress). Matches the SP metadata idGenius publishes, and the User Identity > Auto Detect behavior on the RSA side. Attribute Mapping (JSON) Default mapping is sufficient — idGenius reads the standard MS WS-* claim URIs for email, given name, surname and name. Customize only if the RSA application has been configured to emit additional Statement Attributes that idGenius should honor. Sign AuthnRequests Off (default). Turn on only when the matching RSA option (SP signs SAML requests) has been enabled, and an SP signing certificate has been uploaded on the RSA side.
Default attribute mapping payload:{ "email": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress", "first_name": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname", "last_name": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname", "name": "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" } - At the bottom of the dialog, enable both toggles: Enabled (turns the provider on for runtime authentication) and Auto-link accounts by email (lets a returning SAML subject bind to an existing idGenius account that shares the same primary email, without requiring the user ever to have set a local password). Click Update Configuration (or Create Configuration on a new row).
Figure 6. Edit SAML Configuration — Enabled and Auto-link toggles, with the IdP-secret-not-shown advisory note.
- Verify the provider row in the SAML Providers list shows Status = Enabled, Auto-link = On, IdP Entity ID populated, and the expected email-domain list.
Notes
- If both a My Page SSO Application and a Relying Party exist on the same RSA tenant for idGenius, only one of them can be wired into idGenius at a time — the IdP Entity ID is unique per idGenius SAML provider row.
To migrate from one mode to the other, edit the existing idGenius SAML provider, paste the new IdP Entity ID / SSO URL / certificate, and save. Existing user sessions remain valid; the next SP-initiated SAML transaction uses the new RSA target. - Auto-link by email assumes the SAML NameID (email) is unique within idGenius. Duplicate email entries cause the first match to win, which may not be the intended account. Use the idGenius Record Unification rules to keep primary email values unique across HIDs. The companion SCIM integration enforces this constraint when it is the source of truth for user objects.
Verification and Sign-in Test
After both ends have been saved (Published the changes), validate the round-trip using a browser that does not currently have an idGenius session.
- Open https://<idgenius-tenant>.idgenius.io in a private/incognito window.
- Either type a registered email-domain address and click Continue (idGenius auto-discovers the SAML provider and redirects), or click Sign in with SSO to be shown the SAML provider chooser.
- On the RSA-hosted IdP page, complete the primary authentication and any factor steps enforced by the bound Access Policy.
- RSA POSTs a signed SAML response to https://<idgenius-api-host>.idgenius.io/api/auth/saml/acs.
- idGenius validates the signature against the stored IdP certificate, reads the email NameID, auto-links to the existing local account, and lands the user on the idGenius dashboard.
Audit evidence captured by both sides
- RSA — Platform > User Event Monitor records the SSO transaction with the SP Entity ID, the authentication factors used, and the applied Access Policy.
- idGenius — Settings > Administration > Audit Log records the incoming SAML response, the auto-link decision, and the session start for the bound local user.
Common failure modes and remediation
- "SAML validation failed" in idGenius — the IdP certificate stored in idGenius does not match the certificate RSA is actually using. Re-download from the RSA Message Protection block and re-paste.
- "Audience restriction not satisfied" — the ACS URL or SP Entity ID in RSA does not match what idGenius is sending. Both values are case- and scheme-sensitive.
- "Issuer mismatch" / silent failure — the RSA-side change was not published. Confirm the "Status: Success" banner and the Publish Changes button in the RSA console header.
Related Articles
Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 641Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 259Number of Views Palo Alto NGFW Global Protect - SAML Relying Party Configuration - RSA Ready Implementation Guide 130Number of Views Citrix NetScaler - SAML Relying Party Configuration - RSA Ready Implementation Guide 11Number of Views Microsoft Entra ID - SAML Relying Party Configuration - RSA Ready Implementation Guide 100Number of Views
Trending Articles
RSA SecurID software token .sdtid file fails to import into RSA SecurID Software Token 5.0 for Windows Customizing TLS Protocol Version RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device RSA Release Notes for RSA Authentication Manager 8.8