Configuring SAML SSO with Box and PingOne for Enterprise
Learn how to configure SAML SSO with Box and PingOne for Enterprise.
About this task
The following table details the required and optional attributes to be configured in the assertion attribute contract.
Attribute Name | Description | Required / Optional |
---|---|---|
|
Required |
|
|
First Name |
Optional |
|
Last Name |
Optional |
|
Groups |
Optional |
The following configuration is untested and is provided as an example. Additional steps might be required. |
Create a PingOne for Enterprise application for Box
-
Download the Box metadata from https://cloud.app.box.com/s/9y0zm1sqgvkxe8ha2qa3dfhwoivpoyy4.
-
Sign on to PingOne for Enterprise and click Applications.
-
On the SAML tab, click Add Application.
-
Click Search Application Catalog and search for
Box
. -
Click the Box row.
-
Click Setup.
-
Select the appropriate signing certificate.
-
Review the steps, and note the PingOne for Enterprise SaaS ID, IdP ID, Initiate Single Sign-on (SSO) URL, and Issuer values.
-
Click Continue to Next Step.
-
In the Upload Metadata section, click Select File, and upload the Box metadata file that you downloaded.
-
Ensure that ACS URL is set to
https://sso.services.box.net/sp/ACS.saml2
and Entity ID is set tobox.net
.
-
-
Click Continue to Next Step.
-
In the Attribute Mapping section, in the Identity Bridge Attribute or Literal Valuecolumn of the SAML_SUBJECTrow, select the attribute SAML_SUBJECT.
-
Complete the remaining attribute mappings for givenName, sn, memberOf, and title.
-
Click Continue to Next Step.
-
Update the Name, Description, and Category fields as required.
-
Click Continue to Next Step.
-
Add suitable user groups for the application.
-
Click Continue to Next Step.
-
Review the settings.
-
Copy the Single Sign-On (SSO) URL value to a temporary location.
This is the IdP-initiated SSO URL that you can use for testing.
-
On the SAML Metadata row, click Download. You will use this for the Box configuration.
-
Click Finish.
Configure the PingOne for Enterprise IdP connection for Box
-
Sign on to the Box Admin Console as an administrator.
-
Click Enterprise Settings.
-
Click the User Settings tab.
-
In the Configure Single sign-on (SSO) for All Users section, click Configure.
-
Click I don’t see my provider, or don’t have a metadata file.
-
Complete the Box SSO Setup Support Form:
-
Review the request form and the For faster service please read section.
-
Complete all the required fields.
-
For Who is your Identity Provider, select Other with Metadata.
-
For What is the attribute for the user’s email?, select SAML_SUBJECT.
-
For What is the attribute for groups?, select memberOf.
-
For What is the attribute for the user’s first name?, select givenName.
-
For What is the attribute for the user’s last name?, select Sn.
-
Attach the metadata that you downloaded from the PingOne for Enterprise configuration.
-
-
Click Submit.
-
-
After the Box support team completes the configuration, follow any provided instructions and test the integration.