This section describes how to integrate RSA SecurID Access with RSA Governance and Lifecycle using a SAML SSO Agent.
Architecture Diagram
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to RSA Governance and Lifecycle. During configuration of the IdP you will need some information from the SP. This information includes (but is not limited to) Assertion Consumer Service URL and Service Provider Entity ID.
Procedure
-
Sign into RSA Cloud Administration Console and browse to Applications > Application Catalog, select RSA Governance and Lifecycle and click Add.
-
Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.
-
Navigate to Initiate SAML Workflow section.
-
In the Connection URL field, enter the url https://%HOST_NAME%/aveksa/main and replace the HOST_NAME with your RSA G&L hostname.
-
-
Scroll down to SAML Identity Provider (Issuer) section. Click Generate Cert Bundle, enter the Common Name and Generate and Download the certificate. This certificate will be required in Step 4 of Configure SAML in RSA Governance and Lifecycle section.
-
Identity Provider URL - <Automatically generated>
-
Issuer Entity ID - <Automatically generated>
-
Select Choose File and upload the private key.
-
Select Choose File to import the public signing certificate.
-
-
Scroll down to the Service Provider section.
-
Assertion Consumer Service (ACS) - Enter the Assertion Consumer url as https://%HOST_NAME%/aveksa/main and replace the HOST_NAME with your RSA G&L hostname.
-
Audience (Service Provider Entity ID) - Enter the entity id as https://%HOST_NAME%/aveksa/main and replace the HOST_NAME with your RSA G&L hostname.
-
-
Scroll to the User Identity section, select the following values.
- Identifier Type – transient
-
Identity Source – name of your user identity source
-
Property – sAMAccountName
-
Click Next Step.
-
On the User Access page, select Allow All Authenticated Users radio button.
-
Click Next Step.
-
On the Portal Display page, select Display in Portal.
-
Click Save and Finish.
-
Click Publish Changes.
Configure SAML in RSA Governance and Lifecycle
Perform these steps to configure RSA Governance and Lifecycle as an SSO Agent SAML SP to RSA Cloud Authentication Service.
Procedure
-
Log onto your RSA Governance and Lifecycle account using administrative credentials.
-
From the navigation bar, navigate to Admin > System > Authentication. Click on Create Authentication Source.
-
On the Create New Authentication Service page, enter name of the your authentication source in Authentication Source Name and select SSO SAML from Authentication Type drop down. Click Next.
-
On the Configuration Information page, enter the following values:
-
IdentityURL: Enter the Identity Provider URL from Step 4 of Configure RSA Cloud Authentication Service section.
-
AveksaURL: Enter the Connection URL from Step 3 of Configure RSA Cloud Authentication Service section.
-
IDPCertificate: Browse and select the certificate generated in Step 4 of Configure RSA Cloud Authentication Service section.
-
-
Click Finish.
Configuration is complete.
Return to the main page for more certification related information.
Related Articles
Atlassian Jira - SAML My Page SSO Configuration - RSA Ready Implementation Guide 11Number of Views Quick Setup - Configuring IDP-Initiated SAML for Third-Party Application 87Number of Views FortiGate Firewall - SAML IDR SSO Configuration Using Admin Access UI - RSA Ready Implementation Guide 23Number of Views RSA Authentication Manager 8.7 SP1 Azure Virtual Appliance Getting Started 22Number of Views Upload Certificates for Trusted Certificate Authorities 45Number of Views
Trending Articles
An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager Upgrade Process