Single Sign-On (SSO) is a convenient and secure way to authenticate multiple applications using one set of logon credentials through an Identity Provider (IdP). With SSO, you can log on to the Trellix applications directly from your enterprise IdP, making the login process seamless and secure. This eliminates the need for separate login credentials for each application, reducing the risk of password fatigue and increasing productivity.
To configure SSO for your Trellix account:
Configure the IdP application.
Input your Security Assertion Markup Language (SAML) configuration information.
You can configure the account with only one IdP.
Configuring the IdP application
Configure a new application in your SSO solution to get the IdP URL, issuer URL, and X.509 certificate.
For instructions on how to configure your IdP application, see your identity provider's documentation.
Note
You might need to use placeholder information for the ACS URL and the Audience URI when you configure your third-party IdP. Enter the details later when you Update your IdP application SAML settings with the information from ePO - SaaS.
Input your SAML configuration information
Configure the settings in the Identity Provider page to enable SSO using your IdP application.
Enter the information in the Identity Provider section.
Issuer — Enter the Identity Provider Issuer from your IdP.
Certificate — Download the certificate from your IdP, then click Choose File to upload the certificate to ePO - SaaS.
Login URL — Enter the Identity Provider SSO URL from your IdP.
Signature Algorithm — Make sure that your IdP application is configured with signature algorithm — SHA-256.
Request Binding — Make sure that the request binding matches with your IdP application.
After successfully saving the configuration, you can view the information in the Service Provider (Trellix) section.
Audience — Edit your IdP application's SAML settings to update the Audience URI.
Assertion Consumer Service URL — Edit your IdP application's SAML settings to include the SSO URL.
Certificate — Download the certificate. Some IdPs require the ePO - SaaS service provider certificate.
SAML Metadata — Download the SAML metadata. It contains other configuration which your IdP might require.
From the User List, select the users that you want to exempt from SSO.
Note
Configure your IdP application to send these user attributes to the IdP provider. The possible schemas provided here is for reference only. These schemas can vary depending on the IdP provider.
First Name —
user.firstName(Possible schema ofhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/firstnameorhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname)Last Name —
user.lastName(Possible schema ofhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/lastnameorhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname)Email —
user.email(Possible schema ofhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailorhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)Unique User Identifier —
user.email(Possible schema ofhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailorhttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)Set your Unique User Identifier to email address. We only accept email address as the primary identifier for users.
Click the newly configured application to test the logon.
Once you change Unique User Identifier from first name or last name to use an email address, the updated certificate has to be downloaded from IdP application and uploaded again in the Identity Provider.
Troubleshooting SSO
The error message — Misconfigured identity provider. Check your configuration and try again appears during logon if any of these conditions are true.
IdP SSO or Trellix IdP is not configured properly.
The user logon using SSO has not been added to the Trellix tenancy.
Unique User Identifier in IdP application is changed to an email address, the updated certificate is not uploaded again in the Identity Provider.
Contact Technical Support on the Trellix Thrive Portal if you encounter this error.