Configuring SailPoint Human Fabric as a Service Provider
You might already be using a single sign-on solution when you purchase SailPoint Human Fabric. If you want to use SAML to authenticate into SailPoint Human Fabric, you can use one of many SSO solutions as an identity provider and SailPoint Human Fabric as a service provider.
For example, users can authenticate into their identity provider, then federate into SailPoint Human Fabric to perform tasks related to certifications or provisioning. SailPoint Human Fabric is never aware of the user's password, and their information remains secure.
Note
If you plan to use Non-Employee Risk Management in addition to SailPoint Human Fabric, refer to Non-Employee Authentication and Timeouts for additional configuration details.
Prerequisites
-
Users from your identity provider must have identities within SailPoint Human Fabric with matching data.
- To ensure that your users can authenticate, load their SailPoint Human Fabric accounts from the same source you used to load accounts into your identity provider.
- The only exception is if you configure just-in-time account creation in SailPoint Human Fabric.
-
Obtain the following information from your identity provider:
- Entity ID
- Login URL for Post
- Login URL for Redirect
- Logout URL (optional)
- Signing Certificate
Service Provider Configuration
Complete the following steps to configure SailPoint Human Fabric as a service provider.
-
Go to Admin > Global > Security Settings > Service Provider.
-
Leave the Enable Remote Identity Provider option unchecked until you've provided correct values for the Identity Provider Settings below and imported the signing certificate.
-
Under Identity Provider Settings, enter the following:
-
Entity ID - the unique entity ID of your identity provider. The number you enter here must exactly match the SAML metadata EntityID supplied by your identity provider.
-
Login URL for Redirect - the URL where an authentication request is sent using HTTP Redirect binding.
-
Login URL for Post - the URL where an authentication request is sent using HTTP Post binding.
-
(Optional) Logout URL - the URL where SailPoint Human Fabric redirects users after they sign out or when their session expires.
Note
All SailPoint Human Fabric sessions authenticated using an identity provider automatically expire after 90 days.
-
-
If needed, make changes to the following options in SAML Request Options:
-
Identity Mapping Attribute - Set to the attribute you want to use to authenticate users.
If you select a custom identity attribute, that attribute must be configured as searchable.
-
SAML Binding - Set to Post or Redirect depending on what endpoint the authentication request is sent to.
-
SAML NameID - Set to the SAML NameID that your identity provider is expecting.
-
Choose one of the following options:
-
In Authentication Context, select Password, Secured Transported Password, or Unspecified to set the authentication context used by the identity provider.
Note
The authentication context for SailPoint Human Fabric and the identity provider must match.
-
Select the Exclude Requested Authentication Context check box if you don't need to specify a required authentication context in the authentication request.
-
-
-
Under Signing Certificate, select choose a file and select the signing certificate from its location on your device. The certificate you upload must be in PEM format. The Certificate Name and Certificate Expires fields are populated automatically.
-
Check the Enable Remote Identity Provider option at the top of the page.
-
Under Just-in-Time Account Provisioning, select a source and check Enable JIT Provisioning to automatically create an account when users without an account authenticate into SailPoint Human Fabric from another identity provider.
-
Under Hosted Service Provider, copy the Entity ID and SAML URL to your identity provider.
-
If your identity provider allows you to upload service provider metadata, select Download Metadata to download the metadata. Upload it to your identity provider following their process.
-
Select Save.
If your organization is required to use FedRAMP-authorized services, you must encrypt communications between SailPoint Human Fabric and your identity provider.
Testing Service Provider Configuration
Complete the following steps to test the service provider configuration:
-
Sign out of your account and go to the sign in page for your org. You are redirected to your identity provider.
Important
Ensure that you have removed
?prompt=truefrom the end of your URL. -
Sign in to your identity provider. You are automatically redirected to SailPoint Human Fabric and authenticated.
If any part of this test fails, you might have an error in your configuration. Verify that you have completed all fields described here correctly.
When your users navigate to SailPoint Human Fabric, they will be automatically authenticated. If authentication fails, the user will be redirected to an error page.
Note
SailPoint Human Fabric does not support SAML Single Logout (SLO).
Bypassing the Identity Provider
When configuring SailPoint Human Fabric as a service provider, the default behavior is to only allow end users to launch SailPoint Human Fabric after signing in to your identity provider.
However, to ensure continuity of access if your identity provider is unavailable, users with an elevated user level can bypass the identity provider. This means they can either:
- Use your normal federated single-sign on process to authenticate to SailPoint Human Fabric.
- Use a URL that includes
?prompt=trueto navigate directly to the sign-in page to provide authentication credentials there. For example, if the Admin entershttps://[customer].identitynow.com/login/login?prompt=true, they'll view the SailPoint Human Fabric sign-in page.
Encrypting SAML Assertions for FedRAMP
If your organization needs to comply with FedRAMP requirements, you must configure your SSO integration to encrypt the SAML assertions sent between SailPoint Human Fabric and your identity provider.
Note
- This feature is only available in FedRAMP authorized tenants.
- It may be necessary to enable the signing certificate to be used for both signing of SAML responses and assertions.
To encrypt communications between SailPoint Human Fabric and your identity provider:
-
Download the SailPoint Human Fabric Service Provider metadata file containing the public key that will be used to encrypt the SAML assertion.
This can be accessed at:
https://<tenantName>.login.saas.sailpointfedramp.com/saml/metadata/alias/<tenantName>-spWhere
<tenantName>is the name of your tenant. -
Within the downloaded metadata file, copy the text value within the
ds:X509Certificatenode, excluding the tags. -
In a separate text file, add two lines:
-----BEGIN CERTIFICATE----------END CERTIFICATE-----
Paste the copied certificate value between these two lines.
-
Save this file with a
.cerfiletype. -
Go to your identity provider and enable encryption. Upload the
.cerfile you created.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.