---
title: Remote IdP configuration
description: After you've set up a remote IdP, configure it under Native Consoles > Access Management > Realms > Realm Name > Applications > Federation > Entity Providers > Provider Name.
component: pingoneaic
page_id: pingoneaic:am-saml2:saml2-remote-idp-configuration
canonical_url: https://docs.pingidentity.com/pingoneaic/am-saml2/saml2-remote-idp-configuration.html
llms_txt: https://docs.pingidentity.com/pingoneaic/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
section_ids:
  remote-idp-assertion-content: Assertion Content
  signing_and_encryption: Signing and Encryption
  nameid_format: NameID Format
  secrets: Secrets
  basic_authentication: Basic Authentication
  client_authentication: Client Authentication
  remote-idp-services: Services
  idp_service_attributes: IDP Service Attributes
  nameid_mapping: NameID Mapping
---

# Remote IdP configuration

After you've set up a remote IdP, configure it under Native Consoles > Access Management > Realms > *Realm Name* > Applications > Federation > Entity Providers > *Provider Name*.

## Assertion Content

### Signing and Encryption

* Request/Response Signing

  The parts of messages the IdP requires the SP to sign digitally.

* Encryption

  * NameID Encryption – When selected, the SP must encrypt NameID elements.

* Algorithms

  Select the signing, encryption and digest algorithms that the SP will use.

### NameID Format

* NameID Format List

  Supported NameIDs for users shared between providers for single sign-on (SSO).

### Secrets

* Secret Label Identifier – Identifier used to create a secret label for mapping to a secret in the secret store. Advanced Identity Cloud uses this label to create a specific secret label for this entity provider. The secret label takes the form `am.applications.federation.entity.providers.saml2.identifier.basicauth` where identifier is the value of Secret Label Identifier. The label can only contain characters `a-z`, `A-Z`, `0-9`, and periods (`.`). It can't start or end with a period.

  If you change the Secret Label Identifier for a specific entity provider, any corresponding mappings are deleted, unless they're referenced by other entity providers.

### Basic Authentication

* Enabled – Authenticate with the specified username and password when making requests to this entity provider's SOAP endpoints.

* User Name – The username with which to authenticate at SOAP endpoints.

* Password – The password with which to authenticate at SOAP endpoints.

  |   |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
  | - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  |   | If you set a value for Secret Label Identifier, and Advanced Identity Cloud finds a mapping to this secret label in the secret store, the value of this Password field is ignored. For example, if you set the Secret Label Identifier to demo and Advanced Identity Cloud finds a secret mapping to `am.applications.federation.entity.providers.saml2.demo.basicauth`, Advanced Identity Cloud uses this secret and ignores the value of the Password field. For basic authentication, there is no *default* secret label for the realm, or globally. |

### Client Authentication

These settings let an SP authenticate to the IdP using mutual TLS (mTLS).

When you enable client authentication for any request type in this section, you must configure a secret mapping from one of the following secret labels to a valid secret (ESV) in the secret store:

* `am.default.applications.federation.entity.providers.saml2.sp.mtls` – the global or realm-specific mapping for hosted SPs

* `am.applications.federation.entity.providers.saml2.identifier.mtls` – a mapping for a specific SP, where identifier is the value of the Secret Label Identifier you set in the Secrets panel in the SP configuration.

If you configure a global mapping, a realm-specific mapping, and a mapping for a specific SP, the order of precedence is as follows:

* Hosted SP-specific mapping

* Realm-level default

* Global default

The certificates mapped to these labels are included in the SP metadata export with `<KeyDescriptor use="signing">`.

Currently, you can enable mTLS for the following request:

* Artifact Resolve – For artifact resolution requests, the IdP instructs the SP to send a client certificate along with the request.

## Services

### IDP Service Attributes

* Artifact Resolution Service

  The endpoint to manage artifact resolution.

* Single Logout Service

  The endpoints to manage SLO depending on the SAML binding.

  These endpoints are used only for SP-initiated flows but are included as a requirement of the [SAML V 2.0 Metadata specification](http://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf).

* Manage NameID Service

  The endpoints to manage NameIDs depending on the SAML binding.

* Single SignOn Service

  The endpoints to manage SSO.

### NameID Mapping

* URL

  The endpoint to manage NameID mapping.
