Configuring SAML SSO with Egnyte and PingOne for Enterprise
Learn how to enable Egnyte sign-on from the PingOne for Enterprise console (IdP-initiated sign-on) and direct Egnyte sign-on using PingOne for Enterprise (SP-initiated sign-on).
Before you begin
-
Link PingOne for Enterprise to an identity repository containing the users requiring application access.
-
Populate Egnyte with at least one user to test access.
-
You must have administrative access to PingOne for Enterprise and Egnyte.
Update the supplied Egnyte application in PingOne for Enterprise
-
Sign on to PingOne for Enterprise and go to Applications → Application Catalog.
-
Search for
Egnyte
. -
Expand the Egnyte entry and click the Setup icon.
-
Copy the Issuer and IdP ID values.
-
Download the signing certificate.
-
Click Continue to Next Step.
-
Set ACS URL to
https://Your-Egnyte-domain.egnyte.com/samlconsumer/PingIdentity
. -
Click Continue to Next Step twice.
-
In the Attribute Mapping section, map SAML_SUBJECT to the attribute containing the user’s email address.
-
Click Continue to Next Step twice.
-
Click Add for all user groups that should have access to Egnyte.
-
Click Continue to Next Step.
-
Click Finish.
Add the PingOne for Enterprise IdP connection to Egnyte
-
Sign on to your Egnyte Admin organization as an administrator.
-
Click the menu icon and then click Settings.
-
Click the Security and Authentication tab.
-
In the Single sign-on authentication list, select SAML 2.0.
-
In the Identity provider list, select Ping Identity.
-
Set the following values:
Field Value Identity provider login URL
https://sso.connect.pingidentity.com/sso/idp/SSO.saml2?idpid=IdP-ID-value
Identity provider entity ID
The Issuer value from above.
Identity provider certificate
In a text editor, open the signing certificate that you downloaded. Copy and paste the contents.
Default user mapping
Email address
-
Click Save.
-
Go to Settings → Users and Groups.
-
Select the appropriate users and set their AuthType to SSO.