Cisco ISE - SAML Relying Party Configuration - RSA Ready Implementation Guide
Last Modified: 2026-10-05

This article describes how to integrate Cloud Access Service (CAS) with Cisco ISE using SAML Relying Party.

      

Configure CAS

Perform these steps to configure CAS using Relying Party.

Procedure

  1. Sign in to the RSA Cloud Administration Console.
  2. Click Authentication Clients > Relying Parties.
  3. On the My Relying Parties page, click Add a Relying Party.
  4. On the Relying Party Catalog page, click Add for Service Provider SAML. 
  5. On the Basic Information page, enter the application name in the Name field, and then click Next Step.
  6. On the Authentication page, choose RSA manages all authentication.
  7. In the 1.0 Access Policy for Authentication drop-down list, select a policy that was previously configured, and then click Next Step.
  8. Under Data Input Method, choose Enter Manually. 
  9. Scroll down to the Service Provider section and enter placeholder values for the required fields. These values will be automatically updated when you upload the metadata exported from Cisco ISE later. 
    1. Assertion Consumer Service (ACS) URL: Enter any valid URL. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
    2. Service Provider Entity ID: Retain the default value. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
  10. Under the Message Protection section, choose IdP signs entire SAML response.
  11. Click Download Certificate and save the certificate for use later in the Configure Cisco ISE section.
  12. Under Advanced Configuration, scroll down to the User Identity section and select the following values:
    • Identifier Type: Auto Detect
    • Property: Auto Detect

  13. Under Statement Attributes, select the following values:
    • Attribute Name: mail
    • Attribute Source: Identity Source
    • Property: mail

  14. Click Save and Finish.
  15. Locate the newly created Cisco Relying Party and download the RSA metadata that will be imported into the Cisco ISE configuration.
  16. Click Publish Changes and wait for the operation to complete.
    Your application is now enabled for SSO. 

      

Configure Cisco ISE

Perform these steps to configure Cisco ISE.

Procedure

  1. Log in to the Cisco ISE management IP address with admin credentials.
  2. Navigate to Administration > Identity Management > External Identity Sources. 
  3. Under External Identity Sources, choose SAML Id Providers and click Add.
  4. In the new SAML Identity Provider pane, choose an ID Provider Name and an optional description on the General tab.
  5. Under Identity Provider Config., browse to the IdP metadata downloaded from RSA earlier.  
  6. Under Attributes, click Add to add a new attribute that matches the mail attribute configured in the statement attributes in RSA.
    • Name in Assertion: mail
    • Name in ISE: mail
  7. Scroll down and click Save to save the Identity Provider configuration.
  8. Open the newly created configuration.
  9. Navigate to the Service Provider Info. tab.
  10. Under Export Service Provider Information, click Export to export the Cisco ISE metadata.
    Note: Create a separate Identity Provider entity for each Cisco ISE portal, using the unique metadata exported from that portal.
  11. Return to the RSA configuration and edit the Cisco ISE Relying Party that you created. Choose Import Metadata, then upload the metadata file downloaded from Cisco to automatically populate the default fields configured during the initial setup.

The configuration is complete.