SSO Agent - SAML Configuration - Illumio RSA Ready SecurID Access Implementation Guide
This section contains instructions on how to integrate RSA SecurID Access with Illumio using a SAML SSO Agent.
Architecture Diagram
RSA Cloud Authentication Service
Follow the steps in this section to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Illumio.
Procedure
-
Logon to the RSA Cloud Administration Console and browse to Applications > Application Catalog, search for illumio and click +Add to add the connector.
-
Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.
-
Navigate to Initiate SAML Workflow section.
-
Leave the Connection URL field blank.
-
Choose IDP-initiated.
Note: The following IDP-initiated configuration works for SP-initiated Illumio connections as well.
-
Scroll down to SAML Identity Provider (Issuer) section.
-
Select Choose File and upload the private key.
-
Select Choose File to import the public signing certificate.
-
Select the checkbox for Include Certificate in Outgoing Assertion.
-
Scroll down to the Service Provider section.
-
Enter the Assertion Consumer Service (ACS) URL found on Illumio’s Single Sign-On Configuration page.
-
Enter the Illumio Issuer in the Audience (Service Provider Entity ID) field.
-
Scroll down to the User Identity section. Verify the settings are correct for your environment. In this example the NameID is set to format unspecified with the value of mail.
-
Click Show Advanced Configuration.
-
Under Attribute Extension add attributes Email Address, User.FirstName, User.LastName, User.MemberOf with their correlated property.
-
Click Next Step.
-
On the User Access page, select Allow All Authenticated Users user policy from the available options.
-
13. Click Next Step.
-
On the Portal Display page, select Display in Portal.
-
Click Save and Finish.
-
Click Publish Changes. Your application is now enabled for SSO. Note: If you make any additional changes you will need to republish the changes.
Illumio
Follow the steps in this section to configure Illumio as an SSO Agent SAML SP to RSA Cloud Authentication Service.
Procedure
-
Login into the Illumio administration console.
-
Navigate to Access Management > Authentication.
-
Select SAML then click Configure.
-
Click Edit.
-
Paste the public certificate in the SAML Identity Provider Certificate field.
-
Enter the Identity Provider URL in the Remote Login URL field.
-
Enter the Logout Landing URL.
-
In the Authentication Method select Password Protected Transport.
-
Click Save.
Configuration is complete.
Return to the main page for more certification related information.
Related Articles
Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 243Number of Views ScreenSteps - SAML SSO Agent Configuration - SecurID Access Implementation Guide 3Number of Views Telemetry TV - SAML SSO Agent Configuration - SecurID Access Implementation Guide 3Number of Views RSA Governance and Lifecycle - SAML SSO Agent Configuration - RSA Ready SecurID Access Implementation Guide 36Number of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records Unable to login to RSA Authentication Manager Security Console as super admin RSA Authentication Manager 8.9 Release Notes (January 2026) How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Connection fails to Cloud Authentication Service when connecting through a proxy server from RSA Authentication Manager to…