Once you have downloaded and installed the ePO - SaaS Cloud Bridge extension on your ePO - On-prem server, you can then configure your ePO - On-prem to enable log on using ePO - SaaS credentials.
Ensure that you have a valid ePO - SaaS account with Trellix Cloud Administrator permissions.
If you have other Identify Provider configured in ePO - SaaS, note that you cannot use the IdP credentials to configure ePO - On-prem logon. You must use a valid customer ID.
Log on to the ePO - On-prem server as an administrator.
Select Menu → Configuration → Server Settings, then select Trellix ePO - SaaS Cloud Bridge from Setting Categories. The Trellix ePO - SaaS Cloud Bridge Server Settings page displays these options:
Status — Displays the status of your ePO - SaaSconnection. See Status Messages for detailed status information.
Note
Before you configure your connection, the status is
Not linked.Refresh — Refreshes the interface with the current data and status from the ePO - On-prem database.
Linked Account — Displays the email address of the linked ePO - SaaS account.
Add the ePO - SaaS users who want to access ePO - On-prem via Log On With ePO - SaaS using the following steps —
Select Menu → User Management → User, then click New User button.
In the User name field, type the email address of your ePO - SaaS account.
Under Authentication type, select ePO - SaaS Authentication.
Under Manually assigned permission sets, assign a permission set for the user.
Click Save.
Upon successful creation of the user, log off from the ePO - On-prem console.
From the Trellix ePO - SaaS Cloud Bridge Server Settings page, click Edit.
Enter the ePO - SaaS account email and password.
In the ePO Logon URL section, enter the ePO - On-prem URL which you are using to access the on-premises ePO - On-prem server.
Click Save.
Note
The ePO - SaaS Cloud Bridge settings page now contains a field ePO Logon URL which can be seen only from ePO - On-prem 5.10.0 Update 7 onwards. This URL is added to the allowed URL list in Identity and Access Management (IAM). This is needed for IAM to redirect the user to the on-premises ePO - On-prem after authentication using Log On With ePO - SaaS feature.
The ePO - SaaS Cloud Bridge Server Settings page displays the status as This server is actively linked, and the linked account as the email address for the SaaS account:
Status — After configuration, the status is modified to
This server is actively linked.Linked Account — The email address configured for the ePO - SaaS account.
Trellix ePO - SaaS Customer ID — The ePO - SaaS Customer ID that is linked.
ePO Logon URL — Your ePO - On-prem URL which you are using to access the ePO - On-prem server.
Your ePO - On-prem server is now connected to the ePO - SaaS account.
Note
You might see some error messages while linking your ePO - On-prem account with the ePO - SaaS account. For more information, see Common error messages while linking ePO - On-prem with ePO - SaaS account.