This section describes how to integrate RSA SecurID Access with Vmware Workspace One using a SAML SSO Agent.
Architecture Diagram
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as an SSO Agent SAML IdP to Vmware Workspace One.
Procedure
-
Sign into RSA Cloud Administration Console and browse to Applications > Application Catalog, search for VmwareWorkspace One and click +Add to add the connector.
-
Enter a name for the application in the Name field on the Basic Information page and click the Next Step button.
-
Download the SP Metadata from Workspace One and import it by Import Metadata
-
Navigate to Initiate SAML Workflow section.
-
In the Connection URL field, verify the default setting.
-
b. Choose SP-Initiated.
-
Select Binding Methods as Redirect
-
-
Scroll down to SAML Identity Provider (Issuer) section.
-
Identity Provider URL - Automatically generated
-
Issuer Entity ID - Automatically generated
-
In SAML Response Signature section, click on Generate Cert Bundle
-
Select Choose File and upload the private key.
-
Select Choose File to import the public signing certificate.
-
-
Make sure Include Certificate in Outgoing Assertion is unchecked.
-
Scroll down to the Service Provider section.
-
Assertion Consumer Service (ACS) - Automatically generated by Importing Metadata
-
Audience (Service Provider Issuer ID) – Automatically generated by Importing Metadata
-
Identifier Type – Subject
-
Identity Source – Select the available Identity Source
-
Property – sAMAccountName
-
Click Next Step.
-
Select the Access Policy
-
Click Next Step.
-
On the Portal Display page, select Display in Portal.
-
Click Save and Finish.
-
Click Publish Changes.
-
Navigate to Applications > My Applications.
-
Locate VmwareWorkspace One in the list and from the Edit option, select Export Metadata.
Configure Vmware Workspace One
Perform these steps to configure Vmware Workspace One as an SSO Agent SAML SP to RSA Cloud Authentication Service.
Procedure
-
Logon to VMware Identity Manager Administrator console and browse to Identity & Access Management > Identity Providers
-
Click Add Identity Provider and then click Create SAML IDP
-
Configure the Workspace Oneas Service Provider as follows
-
Identity Provider Name - Add a name to Identity Provider ex. RSA SecurID
-
Binding Protocal - HTTP Redirect
-
SAML Metadata - Import the RSA SecurID Cloud Authentication Service Metadata which is exported from IDP configuration and click Process IDP Metadata
-
Name ID Policy in SAML Request - urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
-
Check the Send Subject in SAML Request.
-
Check the Use Name ID format mapping for Subject.
-
Network - Check the networks this IdP can be accessed from.
-
Authentication Methods - Add a Auth Method with SAML context as urn:oasis:names:tc:SAML:2.0:ac:classes:Password
-
-
Click Save
Next Step: Proceed to the Use Case Configuration Summary section for information on how to apply the SAML SSO Agent configuration to your use case.
Return to the main page for more certification related information.
Related Articles
Vmware vSphere vCenter 6.7 - Authentication Agent Configuration - RSA Ready SecurID Access Implementation Guide 196Number of Views RADIUSwith AM Configuration - Cisco FTD RSA Ready SecurID Access Implementation Guide 82Number of Views VMware vSphere/vCenter 8.0.2 - Authentication Agent Configuration - RSA Ready Implementation Guide 131Number of Views VMware Workspace ONE - SecurID Access Implementation Guide 18Number of Views Vmware Workspace One - Relying Party Configuration - RSA Ready SecurID Access Implementation Guide 17Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide