OneLogin - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.Procedure
- Enable My Page SSO by accessing the RSA Cloud Administration Console > Access > My Page > Single Sign-On (SSO). Ensure it is enabled and protected using two-factor authentication - Password and Access Policy.
- On the Applications > Application Catalog page, search for OneLogin and click Add to add the connection.
- On the Basic Information page, enter a name for the configuration in the Name field and click Next Step.
- On the Connection Profile page, click the IdP-initiated option.
- Provide the Service Provider details in the following format:
- ACS URL: https://<your-subdomain>.onelogin.com/access/idp.
- Service Provider Entity ID: <OneLogin Entity ID>
Refer to the Configure OneLogin section to obtain ACS URL and Entity ID.
- In the SAML Response Protection section, choose IdP signs assertion within response.
- Download the certificate by clicking Download Certificate.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: Auto Detect and Property: Auto Detect.
- Under the Statement Attributes section, add the attributes as shown in the following figure.
- Click Next Step.
- Choose your desired Access Policy for this application and click Next Step > Save and Finish.
- On the My Applications page, click the Edit drop-down icon and select Export Metadata to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure OneLogin
Perform these steps to configure OneLogin.Procedure
- Log on to OneLogin with administrator credentials.
- Click Administration.
- Click Authentication and select Trusted IdPs.
- Click New Trust.
- Provide a name for the IdP and click the green tick icon.
- Under the Configurations section, provide the following details:
- Issuer – The EntityID value that can be obtained from the metadata file downloaded from RSA.
- Email Domains – Provide one or more domains, separated by commas. Authentication will be initiated for users who enter any email address with one of these domains.
- Select the Sign users into OneLogin checkbox.
- Under the SAML Configurations section, provide the following:
- IdP Login URL – The SingleSignOnService value that can be obtained from the metadata file downloaded from RSA.
- SP Entity ID – Use this value while configuring RSA.
- Obtain the your-subdomain value from the SP Entity ID that is used to construct the ACS URL. The your-subdomain value is found in https://<your-subdomain>. onelogin.com.
- To construct the ACS URL, copy the your-subdomain value and paste it into the following URL: https://<your-subdomain>. onelogin.com/access/idp
- Under the Trusted IdP Certificate section, copy and paste the certificate downloaded from RSA.
- Scroll up, select the Enable Trusted IDP checkbox, and click Save.
The configuration is complete.
Return to OneLogin - RSA Ready Implementation Guide.
Related Articles
Delinea - SAML My Page SSO Configuration - RSA Ready Implementation Guide 14Number of Views Microsoft Office 365 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 121Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Salesforce - SAML My Page SSO Configuration - RSA Ready Implementation Guide 66Number of Views AWS IAM - SAML My Page SSO Configuration - RSA Ready Implementation Guide 34Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) Artifacts to gather in RSA Identity Governance & Lifecycle RSA Governance & Lifecycle 8.0.0 Administrators Guide RSA Governance & Lifecycle 8.0.0 Installation Guide
Don't see what you're looking for?