Cisco ISE - SAML Relying Party Configuration - RSA Ready Implementation Guide
Last Modified: 2026-10-05
This article describes how to integrate Cloud Access Service (CAS) with Cisco ISE using SAML Relying Party.
Configure CAS
Perform these steps to configure CAS using Relying Party.
Procedure
- Sign in to the RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the My Relying Parties page, click Add a Relying Party.
- On the Relying Party Catalog page, click Add for Service Provider SAML.
- On the Basic Information page, enter the application name in the Name field, and then click Next Step.
- On the Authentication page, choose RSA manages all authentication.
- In the 1.0 Access Policy for Authentication drop-down list, select a policy that was previously configured, and then click Next Step.
- Under Data Input Method, choose Enter Manually.
- Scroll down to the Service Provider section and enter placeholder values for the required fields. These values will be automatically updated when you upload the metadata exported from Cisco ISE later.
- Assertion Consumer Service (ACS) URL: Enter any valid URL. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
- Service Provider Entity ID: Retain the default value. This URL will be updated automatically later when the Cisco ISE metadata is uploaded.
- Under the Message Protection section, choose IdP signs entire SAML response.
- Click Download Certificate and save the certificate for use later in the Configure Cisco ISE section.
- Under Advanced Configuration, scroll down to the User Identity section and select the following values:
- Identifier Type: Auto Detect
- Property: Auto Detect
- Under Statement Attributes, select the following values:
- Attribute Name: mail
- Attribute Source: Identity Source
- Property: mail
- Click Save and Finish.
- Locate the newly created Cisco Relying Party and download the RSA metadata that will be imported into the Cisco ISE configuration.
- Click Publish Changes and wait for the operation to complete.
Your application is now enabled for SSO.
Configure Cisco ISE
Perform these steps to configure Cisco ISE.
Procedure
- Log in to the Cisco ISE management IP address with admin credentials.
- Navigate to Administration > Identity Management > External Identity Sources.
- Under External Identity Sources, choose SAML Id Providers and click Add.
- In the new SAML Identity Provider pane, choose an ID Provider Name and an optional description on the General tab.
- Under Identity Provider Config., browse to the IdP metadata downloaded from RSA earlier.
- Under Attributes, click Add to add a new attribute that matches the mail attribute configured in the statement attributes in RSA.
- Name in Assertion: mail
- Name in ISE: mail
- Scroll down and click Save to save the Identity Provider configuration.
- Open the newly created configuration.
- Navigate to the Service Provider Info. tab.
- Under Export Service Provider Information, click Export to export the Cisco ISE metadata.
Note: Create a separate Identity Provider entity for each Cisco ISE portal, using the unique metadata exported from that portal. - Return to the RSA configuration and edit the Cisco ISE Relying Party that you created. Choose Import Metadata, then upload the metadata file downloaded from Cisco to automatically populate the default fields configured during the initial setup.
The configuration is complete.
Related Articles
Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 718Number of Views Cisco ISE - RSA Ready Implementation Guide 360Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 263Number of Views FortiGate Firewall - SAML Relying Party Configuration Using SSL VPN - RSA Ready Implementation Guide 63Number of Views Fortinet IPsec VPN - SAML Relying Party Configuration – RSA Ready Implementation Guide 10Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide
Don't see what you're looking for?