Cisco ISE - SAML My Page Configuration - RSA Ready Implementation Guide
Last Modified: 2026-10-05

This article describes how to integrate Cloud Access Service (CAS) with Cisco ISE using SAML My Page.

   
Configure CAS

Perform these steps to configure CAS using My Page.

Procedure 

  1. Sign in to the RSA Cloud Administration Console and click Applications > Application Catalog.
  2. Search for the Cisco ISE Portal and then click Add.
  3. On the Basic Information page, choose Cloud.
  4. Enter the name for the application and click Next Step.
  5. On the Connection Profile page, navigate to the Initiate SAML Workflow section and choose IdP-initiated.
  6. Under Data Input Method, choose Enter Manually. 
  7. Scroll down to the Service Provider section and enter placeholder values for the required fields. These values will be automatically updated when you upload the metadata exported from Cisco ISE later. 
    1. Assertion Consumer Service (ACS) URL: Enter any valid URL. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
    2. Service Provider Entity ID: Retain the default value. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
  8. Under the Message Protection section, choose IdP signs entire SAML response.
  9. Click Download Certificate and save the certificate for use later in the Configure Cisco ISE section.
  10. Expand the Connection Profile Advanced Configuration section.
  11. Under User Identity, select the following values: 
    1. Name ID Format: Auto Detect
    2. User Attribute for SAML Response Subject: Auto Detect

  12. Under Statement Attributes, select the following values:
    1. Attribute Name: mail
    2. Attribute Source: Identity Source
    3. Property: mail

  13. Click Next Step.
  14. On the User Access page, choose the access policy you want to use to determine which users can access the application, and then click Next Step.
  15. On the Portal Display page, configure the portal display and other settings, and click Next Step.
  16. On the Fulfillment page, configure your preferred settings or leave the Fulfillment toggle button disabled as it is.
  17. Click Save and Finish.
  18. Locate the newly created Cisco ISE application and download the RSA metadata that should be imported into the Cisco ISE configuration. 
  19. Click Publish Changes and wait for the operation to complete.
    Your application is now enabled for SSO. 

     

Configure Cisco ISE

Perform these steps to configure Cisco ISE.

Procedure

  1. Log in to the Cisco ISE management IP address with admin credentials.
  2. Navigate to Administration > Identity Management > External Identity Sources. 
  3. Under External Identity Sources, choose SAML Id Providers and click Add.
  4. In the new SAML Identity Provider pane, choose an ID Provider Name and an optional description on the General tab.
  5. Under Identity Provider Config., browse to the IdP metadata downloaded from RSA earlier.  
  6. Under Attributes, click Add to add a new attribute that matches the mail attribute configured in the statement attributes in RSA.
    • Name in Assertion: mail
    • Name in ISE: mail
  7. Scroll down and click Save to save the Identity Provider configuration.
  8. Open the newly created configuration.
  9. Navigate to the Service Provider Info. tab.
  10. Under Export Service Provider Information, click Export to export the Cisco ISE metadata.
    Note: Create a separate Identity Provider entity for each Cisco ISE portal, using the unique metadata exported from that portal.
  11. Return to the RSA configuration and edit the Cisco ISE application that you created. Choose Import Metadata, then upload the metadata file downloaded from Cisco to automatically populate the default fields configured during the initial setup.

The configuration is complete.