Differences to be aware of when configuring RSA SecurID Access Cloud IdP vs IDR IdP
Originally Published: 2018-11-07
Last Modified: 2026-06-24
Article Number
Applies To
Issue
The SecurID Access Cloud Authentication Service offers two ways to configure an Identity Provider (IdP) for SAML applications:
- Configure the IDR IdP as described in Add a SAML Application.
- Configure the Cloud IdP as described in Add a Relying Party.
The cloud IdP configuration process is simpler (fewer options) while the IDR IdP is more configurable. Configuration differences may not be readily apparent.
Resolution
| Cloud IdP | IDR IdP |
|---|---|
| Creates its own signing certificate | Admin generates and uploads signing certificate |
| Assertion signatures use the SHA-256 hashing algorithm | Assertion signatures use the SHA-1 hashing algorithm by default. Other algorithms including SHA-256 can be configured. |
| Assertion signing is performed on the“Assertion within response” | Assertion signing defaults to “Entire SAML response” but can be configured to be “Assertion within response” |
| The User Identity NameID type is auto-detected | You must specify the User Identity NameID type |
| Extended Attributes are automatically hunted for in all Identity Sources by default | Extended Attributes must be configured with the specific Identity Source where they can be found |
| IdP URL is found only in the IdP metadata file | IdP URL is auto populated in the configuration page |
| 3rd party Service Provider must support SP-initiated SAML | Supports IdP-initiated or SP-initiated SAML |
| Identity Source User Attributes page must have "Synchronize the selected policy attributes with the Cloud Authentication Service" checked. | This checkbox is not applicable |
Notes
The cloud IdP provides primary and/or additional multi-factor authentication for SaaS applications but does not provide single sign-on.
Related Articles
Quick Setup Guide - Configure IdP-Initiated SAML for Third-Party Application 101Number of Views RSA Authentication Manager 8.6 RADIUS Reference Guide 80Number of Views How to enable logging in to the Cloud Admin Console with the IDR acting as the Third-Party Identity Provider (IdP) 334Number of Views RSA Authentication Manager stuck at startup after configuring Embedded IDR 407Number of Views Failed to deploy RSA IDR - VMware "Error updating httpd.conf" 122Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?