People HR - SAML SSO Agent Configuration - RSA Ready SecurID Access Implementation Guide
This section describes how to integrate RSA SecurID Access with People HR using a SAML SSO Agent.
Architecture Diagram
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to People HR.
Procedure
-
-
Sign into the RSA Cloud Administration Console and browse to Applications > Application Catalog
-
Search for People HR then click on + Add
-
On Basic Information page enter a Name for the application, ie. People HR Then click on Next Step.
-
On Connection Profile page
-
-
In Connection URL field, verify the default setting
-
Choose IDP-Initiated or SP-Initiated
-
-
-
Scroll down to SAML Identity Provider (Issuer) section.
-
Note the Identity Provider URL and Issuer Entity ID. These values are automatically generated. They may be needed later for the configuration of People HR
-
Click on Generate Cert Bundle, set a a common name for your company certificate. Then click Generate and Download
-
Select Choose File and upload the private key from the generated certificate bundle
-
Select Choose File and upload the cert from the generated certificate bundle
-
Select Include Certificate on Outgoing Assertion
-
-
-
Scroll down to Service Provider section
-
Enter the Assertion Consumer Service (ACS) replacing <Domain> with your People HR domain or your instance ofPeople HR For example https://rsa44.peoplehr.net/Pages/Saml/consume.aspx
-
Enter the Audience (Service Provider Issuer ID) replacing <Domain> with your People HR domain or your instance of People HR. For example https://rsa44.peoplehr.net
-
Scroll down to User Identity section
-
Ensure Identifier Type = Email Address, set your Identity Source and Property = mail
-
- Click Next Step
-
-
On User Access page select the Access Policy you require. Allow All Authenticated Users is the least restrictive. Click Next Step
-
-
-
On Portal Display Page
-
Select Display in Portal
-
Upload an Application Icon if you wish
-
Set an Application Tooltip if you wish.
-
Click on Save and Finish
-
-
Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.
-
-
Browse to Application > My Applications
-
Locate newly create application for People HR
-
Click on Down Arrow next to Edit button
-
Select Export Metadata data. This will be used below for People HR configuration.
Configure People HR
Perform these steps to integrate People HR with RSA SecurID Access as a SAML SSO Agent.
Procedure
-
Sign into People HR and browse to Settings > Company
-
Next to Upload 'Single Sign On' SAML meta-data file select Browse and browse to the metadata XML file download above.
-
Navigate to Employees and add your Users
Configuration is complete.
See main page for more certification information.
Related Articles
People HR - SAML Relying Party Configuration - RSA Ready SecurID Access Implementation Guide 9Number of Views Sage HR - SecurID Access Implementation Guide 3Number of Views People HR - RSA Ready SecurID Access Implementation Guide 8Number of Views How can I download other people's certificates into MSIE's Other People Certificate store? 9Number of Views Unification and collectors get stuck at calculating role metrics after applying P01 to Via L&G v7.0.0 13Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Manual synchronization introduced in RSA Authentication Manager 8.2 Service Pack 1 patch 6 Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory How to verify NTP server synchronization is not working in RSA Authentication Manager 8.x RSA Governance & Lifecycle 8.0.0 Installation Guide