Ivanti Pulse Connect 9.1 - SAML SSO Agent Configuration - SecurID Access Implementation Guide
This section describes how to integrate SecurID SecurID Access with Ivanti Pulse Connect using a SAML SSO Agent.
Architecture Diagram
Configure SecurID Cloud Authentication Service
Perform these steps to configure SecurID Cloud Authentication Service as an SSO Agent SAML IdP to Ivanti Pulse Connect.
Procedure
-
Sign into the SecurID Cloud Administration Console.
-
Browse to Applications > Application Catalog, search for Pulse Connect Secure and click +Add to add the connector.
-
Step through the setup pages to configure the connector.
-
Basic Information .
-
Set value for Name.
-
-
Connection Profile.
-
Set value for Connection URL . This is the connection URL defined within Pulse Connect.
-
Note the Value for Identity Provider URL This will be used later in Pulse Connect for configuration.
-
Load or generate the certificates used for SAML Response Signature.
-
set the value for Service Provider URL. This is found/defined below in the Section configuring.
-
set the value for SP Entity IDThis is found/defined below in the Section configuring.
-
-
User Access.
-
choose you required Access policy.
-
-
Portal Display.
-
Change portal URL if you require.
-
Click Save and Finish.
-
-
-
When connector setup is complete Download the IDP Metadata. This can be imported in Pulse Connect to ease configuration.
-
Browse to Applications -> My Applications.
-
Scroll down to the created Application for Pulse Connect Secure.
-
On right hand side choose Edit -> Export Metadata.
-
-
Click on Publish Changes when all final changes have been made. Note if you make additional changes you will have to re-publish the changes.
Configure Ivanti Pulse Connect
Perform these steps to configure Ivanti Pulse Connect as an SSO Agent SAML SP to SecurID Cloud Authentication Service.
Procedure
-
Log into the Pulse Connect Secure Administrator page.
-
Ensure the FQDN is configured for SAML.
-
Browse to System -> Configuration -> SAML.
-
Click on Settings.
-
Review/Update the FQDN for SAML.
-
Save Changes.
-
Click on Update Entity ID's.
-
-
Create New SAML IDP Provider.
-
Browse to System -> Configuration -> SAML.
-
Click on New Metadata Provider.
-
Set Name.
-
Upload Metadata file. This was exported from SecurID previously.
-
Upload Certificate.
-
Ensure Roles is Identity Provider is checked.
-
Save Changes.
-
-
Create an Authentication Server for SAML.
-
Browse to Authentication -> Auth. Servers.
-
Select SAML as the Server type and click on New Server.
-
Set Server Name.
-
Set SAML Version to 2.0.
-
Note the Connect Secure Entity Id. This is the URL will change for each SAML Auth. Server. This value is used in the configuration of the SecurID connector above.
-
Set the Identity Provider Id based on the Configuration Mode. This can be manually entered or choose Metadata from dropdown.
-
Load Certificate corresponding to the certificate configured above.
-
Set Metadata Validity to a reasonable value for your use case.
-
Save and Close.
-
-
Create a User Realm.
-
Browse to Users -> User Realms.
-
Click on New.
-
Enter a unique Name.
-
Set Authentication. Choose the appropriate Authentication Server from the dropdown list.
-
Save Changes.
-
Select Role Mapping Tab and Click on New Rule... to create your required Rule as needed to further restrict access based on your requirements. ie. user name is * to match all user ids. Make sure to Add a Role to the Rule. Users is the default system Role of all users . Click on Save Changes.
-
-
Create a Sign-in Policy.
-
Browse to Authentication -> Signing-In -> Sign-in Policies.
-
Click on New URL....
-
Select User type based on your.
-
Set Sign-in URL. This is the URL for the given Secure Access Service.
-
Select the associated Realm and click Add.
-
Save Changes.
-
Next Step: Proceed to the Use Case Configuration Summary section for information on how to apply the SAML SSO Agent configuration to your use case.
Related Articles
Ivanti Pulse Connect 9.1 - Relying Party Configuration - SecurID Access Implementation Guide 17Number of Views RSA SecurID Authenticator 6.x for Windows Provisioning Guide 40Number of Views RSA Authentication Manager 8.4 Patch 9 Readme 21Number of Views REMINDER: Support for RSA Authenticate App Ends on March 31, 2024 49Number of Views Ivanti Pulse Connect 9.1 - RADIUS with CAS Configuration - SecurID Access Implementation Guide 25Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide