Symantec Privileged Access Manager - SAML Relying Party Configuration - RSA Ready Implementation Guide
This article describes how to integrate Cloud Access Service (CAS) with Symantec Privileged Access Manager using SAML Relying Party.
Configure CAS
Perform these steps to configure CAS
Procedure
- Sign in to RSA Cloud Administration Console.
- Navigate to Authentication Clients > Relying Parties.
- On the Relying Party Catalog page, click Add a Relying Party and click Add for Service Provider SAML.
- On the Basic Information page, enter the name for the application in the Name field and click Next Step.
- On the Authentication tab, choose RSA manages all authentication, and select a Primary Authentication Method and Access Policy as required.
- Click Next Step.
- Specify the following details from Symantec Privileged Access Manager.
- Assertion Consumer Service (ACS URL): https://hostname.SymantecPAM/idp/profile/SAML2/POST/SSO
- Service Provider Entity ID: Unique in both CAS and Symantec Privileged Access Manager.
- Under the Message Protection section, for SAML Response Protection:
- Select the certificate downloaded from Symantec Privileged Access Manager.
- Choose IdP signs the assertion with response.
- Scroll down to the User Identity section and select the following:
- Identifier Type: emailAddress
- Property: mail
- Make a note of the Identity Provider Entity ID, as it is needed for the Symantec Privileged Access Manager configuration.
- Click Save and Finish.
- On the My Relying Parties page, for the created Relying Party, click the Edit drop-down icon and select the Metadata option to download the metadata.
- Click Publish Changes.
Your application is now enabled for SSO.
Configure Symantec Privileged Access Manager
Perform these steps to configure Symantec Privileged Access Manager.
Procedure
- Log in to Symantec Privileged Access Manager with the admin account.
- Browse to Configuration > Security > SAML and provide the following details under SP Configuration.
- Entity ID: It should be unique in both CAS and the Symantec portal.
- Fully Qualified HostName: Specify the CAS hostname here.
- Certificate Key Pair: gkcert.crt. This can be uploaded in the CAS SAML request.
- Navigate to Configured Remote SAML IDP to upload IDP Metadata File, which was downloaded from RSA.
- Click Save to complete the SAML configuration.
- Navigate to Configuration > Security > Certificates > Download from Filename and select the certificate to download it. This needs to be used in CAS configuration.
The configuration is complete.
Related Articles
Symantec Privileged Access Manager - SAML My Page SSO Configuration - RSA Ready Implementation Guide 4Number of Views RSA MFA Agent 9.0 for Microsoft IIS Installation and Administration Guide 299Number of Views Some authenticators are only available "With Additional Purchase" on the RSA SecurID Access Cloud Administration Console's… 74Number of Views RSA Authentication Agent for Web: IIS Authentication Test Fails Due to Node Secret Mismatch with RSA Authentication Manager 507Number of Views LDAP authenticator based on Active Directory Identity Collector fails with the error 'Connection could not be established … 1.38KNumber of Views
Trending Articles
Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA-2026-07: RSA Identity Router Security Update for Third-Party Component Vulnerabilities Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?