Nutanix Prism Central - IDR SSO Configuration using SAML - RSA Ready Implementation Guide
This article describes how to integrate RSA SecurID Access with Nutanix Prism Central using a SAML SSO Agent.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Nutanix Prism Central.
Procedure
- Log in to the RSA Cloud Administration Console and navigate to Applications > Application Catalog.
- Click Create From Template and select SAML Direct.
- Select the Identity Router option.
- On the Basic Information page, enter the name for the application in the Name field.
- Click the Next Step button.
- On the Initiate SAML Workflow section, select the IDP-initiated button.
- On the binding method for SAML Request section, select Redirect if not already selected.
- On the connection URL section, give the base URL of the Nutanix Prism Central till the port number as shown in the following screenshot, it will be of the form https://<IP where Nutanix Prism Central is installed>:<portnumber>/
- In the Identity Provider section, perform the following steps:
-
- Select the default Identity Provider Entity ID if not already selected.
- Click the Generate Cert Bundle button to generate and download a zip file containing the private key and certificate. Unzip the downloaded file to extract the certificate and private key.
- Select the first Choose File and upload the RSA SecurID Access private key.
- Select the second Choose File and upload the RSA SecurID Access public certificate.
- In the Assertion Consumer Service (ACS) URL field, enter value which will be of the form https://<hostname of the IP where Nutanix Prism Central is installed>:<port number>/api/iam/authn/callback.
- In the Audience (Service Provider Entity ID) field, enter value which will be of the form https://<hostname of the IP where Nutanix Prism Central is installed>:<port number>/api/iam/authn.
- In the User Identity section, from the Identifier Type dropdown list, select Email Address.
- Select the name of your user identity source and select the property value as mail.
- In the NameID modification section, make the required changes as per the organization needs.
- In Sign Outgoing Assertion section, select Assertion within response.
- Select the Include issuer NameID Format.
- From the NameID format dropdown list, select Email Address.
- Click the Next Step button.
- On the User Access page, select the access policy.
- Click the Next Step button.
- On the Portal Display page, configure the portal display settings.
- Enter descriptive text about the application in the Application Tooltip field. The portal will display this text when a user passes the cursor over the application’s icon.
- Click the Next Step button.
- Configure the options in Fulfilment tab if needed and then click Save and Finish.
- Click the Publish Changes button in the top left corner of the page and wait for the operation to be completed.
- Search for created application from the list of applications and select Export Metadata from the Edit dropdown list to download an XML metadata file containing your RSA SecurID Access IdP’s metadata.
Note: You will need XML metadata file containing your RSA SecurID Access IdP’s metadata when you configure Nutanix Prism Central.
Configure Nutanix Prism Central
Perform these steps to configure Nutanix Prism Central as an SSO Agent SAML Service provider to RSA Cloud Authentication Service.
Configure Identity Provider
Perform these steps to configure Identity Provider
Procedure
- Log in to Nutanix Prism Central using admin credentials.
- Select Admin Center from the top left corner dropdown and click IAM.
- Select the Idp Configuration tab and select Add Identity Provider.
- Select SAML Identity Provider.
- In the resulting Configure Identity Provider section, click Import Metadata to import the metadata downloaded from RSA and verify the below values are populated and if not populated add it from RSA.
- Configuration Name :Any value (“VIASSO” in this instance)
- Username Attribute :mail
- Email Attribute :mail
- Identity Provider URL: This should be the same as what is provided in RSA .
- Certificate :Certificate, which is used to sign the assertion ,which can be downloaded from RSA if not pre-populated.
- Save the configuration.
Configure Authorization Policy
Perform these steps to configure Authorization Policy
Procedure
- Log in to Nutanix Prism Central using admin credentials.
- Select Admin Center from the top left corner dropdown and click IAM.
- Click Authorization Policies.
- Click Create Authorization Policy.
- Choose the Role and click Next.
- Choose the scope as per your business requirements.
- In the Assign Users tab, select the SAML Identity Provider configuration you have created and type in the emails of the users who need access.
- Click Save.
Return to Nutanix Prism Central- RSA Ready Implementation Guide
Related Articles
Nutanix Prism Central- RSA Ready Implementation Guide 51Number of Views RSA MFA Agent 3.0 for Microsoft AD FS Release Notes (Japanese) 13Number of Views RSA Authentication Manager 8.8 Japanese Online HELP Installation Supplemental Guide 7Number of Views RSA Announces Availability of RSA Authentication Manager 8.2 Language Packs 12Number of Views RSA Announces Availability of RSA Authentication Manager 8.7 SP2 Language Packs 99Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?