OneLogin - SAML Relying Party Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as Relying Party to OneLogin.Procedure
- Sign in to RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the Relying Party Catalog page, click Add a Relying Party and click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- On the Authentication page, choose SecurID manages all authentication.
- Select a Primary Authentication Method and Access Policy as required and click Next Step.
- Provide the Service Provider details in the following format:
- ACS URL: https://< your-subdomain >.onelogin.com/access/idp.
- Service Provider Entity ID: <OneLogin Entity ID>
Refer to the Configure OneLogin section to obtain ACS URL and Entity ID.
- In the SAML Response Protection section, choose IdP signs assertion within response.
- Download the certificate by clicking Download Certificate.
- Click Show Advanced Configuration.
- Under the User Identity section, configure Identifier Type and Property. For example, Identifier Type: Auto Detect and Property: Auto Detect.
- Under the Attribute Extension section, add the attributes as shown in the figure.
- Click Save and Finish.
- On the My Relying Parties page, click the Edit drop-down and select the Metadata option to download the metadata.
- Click Publish Changes. Your application is now enabled for SSO.
Configure OneLogin
Perform these steps to configure OneLogin.Procedure
- Log on to OneLogin with administrator credentials.
- Click Administration.
- Click Authentication and select Trusted IdPs.
- Click New Trust.
- Provide a name and click the green tick icon.
- Under the Configurations section, provide the following details:
- Issuer – The EntityID value that can be obtained from the metadata file downloaded from RSA.
- Email Domains – Provide one or more domains, separated by commas. Authentication will be initiated for users who enter any email address with one of these domains.
- Select the Sign users into OneLogin checkbox.
- Under the SAML Configurations section, provide the following:
- IdP Login URL – The SingleSignOnService value that can be obtained from the metadata file downloaded from RSA.
- SP Entity ID – Use this value while configuring RSA.
- Obtain the your-subdomain value from the SP Entity ID that is used to construct the ACS URL. The your-subdomain value is found in https://<your-subdomain>;. onelogin.com.
- To construct the ACS URL, copy the your-subdomain value and paste it into the following URL: https://<your-subdomain>;. onelogin.com/access/idp
- Under the Trusted IdP Certificate section, copy and paste the certificate downloaded from RSA.
- Scrolluo, select the Enable Trusted IDP checkbox, and click Save.
Return to OneLogin - RSA Ready Implementation Guide.
Related Articles
Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 629Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 259Number of Views Palo Alto NGFW Global Protect - SAML Relying Party Configuration - RSA Ready Implementation Guide 130Number of Views Microsoft Entra ID Custom Controls - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide 214Number of Views AWS IAM Identity Center - SAML Relying Party Configuration - RSA Ready Implementation Guide 12Number of Views
Trending Articles
RSA Authentication Manager 8.9 Setup and Configuration Guide How to 'Trust' the RSA Authentication Manager Security Console Self-Signed Root CA certificate and prevent Cert warnings. RSA Authentication Manager 8.9 Release Notes (January 2026) Configure RSA Authentication Manager as a Secure Proxy Server for Cloud Access Service RSA Authentication Manager Upgrade Process
Don't see what you're looking for?