BeyondTrust Privileged Remote Access - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.Procedure
- Enable My Page SSO by accessing RSA Cloud Administration Console > Access > My Page > Single Sign-On (SSO). Ensure it is enabled and protected using two-factor authentication - Password and Access Policy.
- On the Applications > Application Catalog page, click Create From Template.
- Click Select for SAML Direct.
- On the Basic Information page, enter a name for the configuration in the Name field and click Next Step.
- In the Connection Profile section, click the IdP-initiated option.
- For providing Service Provider details:
- Click Import Metadata and click Choose File.
- Select the file that is downloaded from the Service Provider.
See the Configure BeyondTrust Privileged Remote Access configuration section to download the metadata.
- Review the ACS URL and Service Provider Entity ID values that are auto-filled.
- In the SAML Response Protection section, choose IdP signs entire SAML response.
- Download the certificate by clicking Download Certificate.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: persistent and Property: mail.
- Add the Attributes as shown in the following figure under the Statement Attributes section.
- Click Next Step.
- Choose your desired Access Policy for this application and click Next Step > Save and Finish.
- On the My Applications page, click the Edit drop-down icon and select Export Metadata to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure BeyondTrust Privileged Remote Access
Perform these steps to configure BeyondTrust Privileged Remote Access.Procedure
- Sign in to BeyondTrust Privileged Remote Access as administrator.
- Navigate to Users & Security > SECURITY PROVIDERS.
- Click ADD and select SAML2.
- Provide a Name and select the Enabled checkbox.
- Provide the following information.
- Entity ID: Obtain from the metadata file downloaded from RSA.
- Single Sign-On Service URL: Obtain from the metadata file downloaded from RSA.
- Click UPLOAD CERTIFICATE and upload the certificate that was downloaded from RSA.
- Click DOWNLOAD SERVICE PROVIDER METADATA.
- Under Authorization Settings, select a desired group policy and click SAVE.
Notes
Make sure that the Group policy is configured in the BeyondTrust application.RSA users need to be part of a Group Membership and the group should be the same as BeyondTrust Default Group Policy as shown in the preceding figure.
The configuration is complete.
Return to BeyondTrust Privileged Remote Access - RSA Ready Implementation Guide.
Related Articles
Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Microsoft Office 365 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 121Number of Views Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views Delinea - SAML My Page SSO Configuration - RSA Ready Implementation Guide 14Number of Views CyberArk Password Vault Web Access - SAML My Page SSO Configuration - RSA Ready Implementation Guide 60Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?