Ivanti Pulse Connect 9.1 - SAML SSO Agent Configuration - SecurID Access Implementation Guide
This section describes how to integrate SecurID SecurID Access with Ivanti Pulse Connect using a SAML SSO Agent.
Architecture Diagram
Configure SecurID Cloud Authentication Service
Perform these steps to configure SecurID Cloud Authentication Service as an SSO Agent SAML IdP to Ivanti Pulse Connect.
Procedure
-
Sign into the SecurID Cloud Administration Console.
-
Browse to Applications > Application Catalog, search for Pulse Connect Secure and click +Add to add the connector.
-
Step through the setup pages to configure the connector.
-
Basic Information .
-
Set value for Name.
-
-
Connection Profile.
-
Set value for Connection URL . This is the connection URL defined within Pulse Connect.
-
Note the Value for Identity Provider URL This will be used later in Pulse Connect for configuration.
-
Load or generate the certificates used for SAML Response Signature.
-
set the value for Service Provider URL. This is found/defined below in the Section configuring.
-
set the value for SP Entity IDThis is found/defined below in the Section configuring.
-
-
User Access.
-
choose you required Access policy.
-
-
Portal Display.
-
Change portal URL if you require.
-
Click Save and Finish.
-
-
-
When connector setup is complete Download the IDP Metadata. This can be imported in Pulse Connect to ease configuration.
-
Browse to Applications -> My Applications.
-
Scroll down to the created Application for Pulse Connect Secure.
-
On right hand side choose Edit -> Export Metadata.
-
-
Click on Publish Changes when all final changes have been made. Note if you make additional changes you will have to re-publish the changes.
Configure Ivanti Pulse Connect
Perform these steps to configure Ivanti Pulse Connect as an SSO Agent SAML SP to SecurID Cloud Authentication Service.
Procedure
-
Log into the Pulse Connect Secure Administrator page.
-
Ensure the FQDN is configured for SAML.
-
Browse to System -> Configuration -> SAML.
-
Click on Settings.
-
Review/Update the FQDN for SAML.
-
Save Changes.
-
Click on Update Entity ID's.
-
-
Create New SAML IDP Provider.
-
Browse to System -> Configuration -> SAML.
-
Click on New Metadata Provider.
-
Set Name.
-
Upload Metadata file. This was exported from SecurID previously.
-
Upload Certificate.
-
Ensure Roles is Identity Provider is checked.
-
Save Changes.
-
-
Create an Authentication Server for SAML.
-
Browse to Authentication -> Auth. Servers.
-
Select SAML as the Server type and click on New Server.
-
Set Server Name.
-
Set SAML Version to 2.0.
-
Note the Connect Secure Entity Id. This is the URL will change for each SAML Auth. Server. This value is used in the configuration of the SecurID connector above.
-
Set the Identity Provider Id based on the Configuration Mode. This can be manually entered or choose Metadata from dropdown.
-
Load Certificate corresponding to the certificate configured above.
-
Set Metadata Validity to a reasonable value for your use case.
-
Save and Close.
-
-
Create a User Realm.
-
Browse to Users -> User Realms.
-
Click on New.
-
Enter a unique Name.
-
Set Authentication. Choose the appropriate Authentication Server from the dropdown list.
-
Save Changes.
-
Select Role Mapping Tab and Click on New Rule... to create your required Rule as needed to further restrict access based on your requirements. ie. user name is * to match all user ids. Make sure to Add a Role to the Rule. Users is the default system Role of all users . Click on Save Changes.
-
-
Create a Sign-in Policy.
-
Browse to Authentication -> Signing-In -> Sign-in Policies.
-
Click on New URL....
-
Select User type based on your.
-
Set Sign-in URL. This is the URL for the given Secure Access Service.
-
Select the associated Realm and click Add.
-
Save Changes.
-
Next Step: Proceed to the Use Case Configuration Summary section for information on how to apply the SAML SSO Agent configuration to your use case.
Related Articles
Ivanti Pulse Connect 9.1 - Relying Party Configuration - SecurID Access Implementation Guide 14Number of Views RSA SecurID Authenticator 6.x for Windows Provisioning Guide 40Number of Views RSA Authentication Manager 8.4 Patch 9 Readme 21Number of Views REMINDER: Support for RSA Authenticate App Ends on March 31, 2024 49Number of Views Ivanti Pulse Connect 9.1 - RADIUS with CAS Configuration - SecurID Access Implementation Guide 24Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x