SentinelOne - SAML Relying Party Configuration - RSA Ready Implementation Guide
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as Relying Party to SentinelOne.Procedure
- Sign in to the RSA Cloud Administration Console.
- Navigate to the Authentication Clients menu, and from the dropdown, select Relying Parties.
- In the Relying Party Catalog, select Add a Relying Party and click Add for Service Provider SAML
- On the Basic Information page, enter a name for the application in the Name field and click Next Step.
- In the Authentication tab, select SecurID manages all authentication.
- Select the Primary Authentication Method and Access Policy for Additional Authentication as required and click Next Step.
- Provide the Service Provider details in the following format:
- Assertion Consumer Service (ACS) URL: https://<tenant ID>.sentinelone.net/web/api/v2.0/users/login/sso-saml2/<application ID>.
- Service Provider Entity ID: https://<; tenant ID >.sentinelone.net/sso_service_provider/<application ID>
Refer to Notes section to obtain the Tenant ID and Application ID.
- In the SAML Request Protection section, select the SP signs SAML requests checkbox. Then, click Choose File to select the certificate obtained from the SP.
- In the SAML Response Protection section, select IdP signs assertion within response, and download the certificate by clicking Download Certificate.
- Under the User Identity section, select Show Advanced Configuration, then configure Identifier Type and Property as follows:
- Identifier Type: Auto Detect
- Property: Auto Detect
- Click Save and Finish.
- On the My Relying Parties page, click Edit dropdown and select Metadata option to download the metadata.
- Click Publish Changes to save your settings. After publishing, your application will be enabled for SSO.
Notes
To obtain the Assertion Consumer Service URL, Entity ID, and certificate from SentinelOne, follow the step:- Go to Admin dashboard > Settings > Integration > SSO. Copy the URLs and download the certificate for the IdP configuration.
Configure SentinelOne
Perform these steps to configure SentinelOne.Procedure
- Log in to SentinelOne using Advanced or Enterprise credentials - https://SentinelOne.com
- Click Settings at the bottom left corner of the dashboard.
- Click the INTEGRATIONS tab, select SSO, then click the Enable SSO toggle button.
- Click Add Domain and provide a domain name.
- Provide the following details and select the Sign SAML Request checkbox.
- IDP Redirect URL: The value of SingleSignOnService, obtainable from the metadata file downloaded from the RSA platform.
- IssuerID: The value of EntityID, obtainable from the metadata file downloaded from the RSA platform.
- IDP Public Certificate: Upload the certificate downloaded from the RSA platform.
- Select IDP Authentication and click the Test button.
- After the SSO Test passed! message appears, click Save.
Return to SentinelOne - RSA Ready Implementation Guide
Related Articles
SentinelOne - RSA Ready Implementation Guide 6Number of Views SentinelOne - SAML My Page SSO Configuration - RSA Ready Implementation Guide 16Number of Views RSA July 2024 Release Announcements 80Number of Views What are steps to use Microsoft CA with a SID800? 84Number of Views ID Plus Plans - Legacy 161Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?