Ivanti Pulse Connect 9.1 - Relying Party Configuration - SecurID Access Implementation Guide
This section describes how to integrate SecurID Access with Ivanti Pulse Connect using relying party. Relying party uses SAML 2.0 to integrate SecurID Access as a SAML Identity Provider (IdP) to Ivanti Pulse Connect SAML Service Provider (SP).
Architecture Diagram
Configure SecurID Cloud Authentication Service
Perform these steps to configure SecurID Access Cloud Authentication Service as a relying party SAML IdP to Ivanti Pulse Connect.
Procedure
-
Sign into the SecurID Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Partyat the top right.
-
For each section enter the required Relying Party information.
-
Basic Information: Name for the Relying Party Authentication Client.
-
Authentication:
-
Authentication Details: Choose RSA SecurID manages all authentication.
-
Primary Authentication Method: Choose the appropriate Method. Note you cannot choose Determined by Service Provider at Run Time.
-
Select the appropriate Access Policy For Additional Authentication base on your use case.
-
-
Connection Profile.
-
Assertion Consumer Service (ACS) URL : Enter the value obtained from the Pulse Connect Auth. Server configuration below.
-
Service Provider Entity ID :Enter the value obtained Connect Secure Entity Idfrom the Pulse Connect Auth. Server configuration below.
-
Under Message Protection: Download Certificate this Identity Provider Certificate will be used below in the Pulse Connect Auth. Server configuration below.
-
Under Advanced Configuration Note the Entity ID for the Identity Provider this will be used below in the Pulse Connect configuration.
-
-
Click Save and Finish.
-
Click Publish Changes in the upper left hand side of the Administrator console when all changes have been finalized. Note if you make additional changes you will have to re-publish.
-
Configure Ivanti Pulse Connect
Perform these steps to configure Ivanti Pulse Connect as a Relying Party SAML SP to SecurID Cloud Authentication Service.
Procedure
-
Log into the Pulse Connect Secure Administrator page.
-
Ensure the FQDN is configured for SAML.
-
Browse to System -> Configuration -> SAML.
-
Click on Settings.
-
Review/Update the FQDN for SAML.
-
Save Changes.
-
Click on Update Entity ID's.
-
-
Create an Authentication Server for SAML.
-
Browse to Authentication -> Auth. Servers.
-
At New Select SAML Server as the Server type and click on New Server....
-
Set Server Name.
-
Set SAML Version to 2.0.
-
Note the Connect Secure Entity Id. This is the URL will change for each SAML Auth. Server. This value is used in the configuration of the SecurID connector above.
-
Set the Identity Provider Id from the Entity ID for the Identity Provider above.
-
Set the Identity Provider Single Sign On Service URL from the Entity ID for the Identity Provider above.
-
Upload Certificate Browse and open the Identity Provider Certificate downloaded from above.
-
Set Metadata Validity to a reasonable value for your use case.
-
Save and Close.
-
-
Create a User Realm.
-
Browse to Users -> User Realms.
-
Click on New.
-
Enter a unique Name.
-
Set Authentication. Choose the appropriate Authentication Server created in Step 3 from the drop-down list.
-
Save Changes.
-
Select Role Mapping Tab and Click on New Rule... to create your required Rule as needed to further restrict access based on your requirements. ie. user name is * to match all user ids. Make sure to Add a Role to the Rule. Users is the default system Role of all users . Click on Save Changes.
-
-
Create a Sign-in Policy.
-
Browse to Authentication -> Signing-In -> Sign-in Policies.
-
Click on New URL....
-
Select User type based on your.
-
Set Sign-in URL. This is the URL for the given Secure Access Service.
-
Select the associated Realm and click Add.
-
Save Changes.
-
Next Step: Proceed to the Use Case Configuration Summary section for information on how to apply the Relying Party configuration to your chosen use case.
Related Articles
Ivanti Pulse Connect 9.1 - SAML SSO Agent Configuration - SecurID Access Implementation Guide 13Number of Views RSA SecurID Authenticator 6.x for Windows Provisioning Guide 40Number of Views RSA Authentication Manager 8.4 Patch 9 Readme 21Number of Views REMINDER: Support for RSA Authenticate App Ends on March 31, 2024 49Number of Views Ivanti Pulse Connect 9.1 - RADIUS with CAS Configuration - SecurID Access Implementation Guide 25Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide