Security Assertion Markup Language (SAML) single sign-on (SSO) uses third-party authentication service providers to provide access to users. SAML SSO works by transferring the user's identity from the identity provider (IDP) to the authentication service provider, through the exchange of digitally signed XML metadata. To configure the SAML SSO settings for your organization, perform the following steps:
Prerequisites
You must be an Organization Administrator to perform this operation.
Procedure
- From the VMware Pulse IoT Center UI, go to Settings and select Identity and Access.
The
Identity and Access Settings page for your organization is displayed.
- To use an external identity provider to manage authentication for your organization, select Enable External Identity Provider.
- From the IDP Type drop-down menu, select SAML.
- By default, Enable JIT user creation is enabled. With this option enabled, VMware Pulse IoT Center creates a shadow user if the user does not exist in any of the organizations. If you disable this option, the user cannot access VMware Pulse IoT Center even though the user credentials are configured in the external IDP. All valid IDP users can log in to VMware Pulse IoT Center when this option is enabled. To disable Just In Time (JIT) user creation, deselect Enable JIT user creation.
Note: If you decide to update the JIT user creation settings at a later stage, you must reconfigure the SAML settings.
- Under SAML Settings, perform the following steps:
- To save the changes, click SAVE.
Results
You have successfully configured the SAML SSO authentication settings in VMware Pulse IoT Center.