PurelyHR - SAML Relying Party Configuration - SecurID Access Implementation Guide
This section describes how to integrate SecurID Access with PurelyHR using Relying Party. Relying party uses SAML 2.0 to integrate SecurID Access as a SAML Identity Provider (IdP) to PurelyHR SAML Service Provider (SP).
Architecture Diagram
Configure SecurID Access Cloud Authentication Service
Perform these steps to configure SecurID Access Cloud Authentication Service(CAS) as a relying party SAML IdP to PurelyHR .
Procedure
-
Sign into the Cloud Administration Console and browse to Authentication Clients > Relying Parties and click Add a Relying Party.
-
On Basic Information page enter a Name for the application, ie. PurelyHR Then click on Next Step.
-
On Authentication page.
-
select the RSA SecurID Access manages all authentication.
-
Select the desired Primary Authentication Method from the dropdown list.
-
Select the desired policy from the Access Policy for Additional Authentication.
-
Click Next Step.
-
-
On Connection Profile page.
-
Under the Service Provider Metada section.
-
Enter the Assertion Consumer Service (ACS) . This is based on your specific domain of your PurelyHR instance. The URL is https://<domain>.purelyhr.com/sso-consume. For example https://myrsademo.purelyhr.com/sso-consume.
-
Enter the Service Provider Entity ID. This is based on your specific domain of your PurelyHR instance. The URL is https://<domain>.purelyhr.com. For example https://myrsademo.purelyhr.com.
-
Click on Download Certificate. This will be used below in the PurelyHR configuration.
-
Click on Choose File and upload the certificate just downloaded. This same certificate may be used in the PurelyHR configuration below.
-
Open Advanced Configuration section.
-
For Identifier Type Email Address choose mail for the Property.
-
Click on Add.
-
Set Attribute Name to Email and Property to mail.
-
Click on Add.
-
Set Attribute Name to Lastname and Property to sn.
-
Click on Add.
-
Set Attribute Name to Firstname and Property to givenName.
-
Note Property values may be different based on your SecurID CAS configuration.
-
Note the Identity Provider Entity ID field . For Example :https://rsa-blr-per.auth-demo.securid.com/saml-fe/sso.
-
Click on Save and Finish.
-
-
Browse to Authentication Clients > Relying Parties
-
Scroll down to the your newly created Relying party and click down arrow to Edit and choose View or Download IdP MetatData and save off the metadata information.
-
Click on Publish Changes. Your application is now enabled for SSO. If you make any additional changes to the application configuration you will need to republish.
Configure PurelyHR
Perform these steps to integrate PurelyHR with SecurID Access as a Relying Party SAML SP.
Procedure
-
Sign into PurelyHR and browse to SSO SETTINGS.
-
From the Connector dropdown choose Generic SAML.
-
For the X.509 Certificate copy and paste the contents of the downloaded Certificate from the SecurID Access CAS configuration.
-
For IDP Issuer URL provide the value of the Identity Provider Entity ID from the SecurID Access CAS configuration. For example, https://rsa-test.auth-demo.securid.com/saml-fe/sso.
-
For IDP Endpoint URL provide the value of the Identity Provider Entity ID from the SecurID Access CAS configuration. For example, https://rsa-test.auth-demo.securid.com/saml-fe/sso.
-
Keep Force SSO option unselected, to allow non-SAML based authentications to continue to work.
-
Keep Auto-create Users option the default.
-
Save changes.
Configuration is complete.
Next Step: See main page for more certification information.
Related Articles
Add a Relying Party 31Number of Views Relying Parties 50Number of Views Manage Relying Parties 34Number of Views Cloud Access Service - Relying Parties 11Number of Views Okta - SAML Relying Party Configuration - RSA Ready Implementation Guide 45Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x