---
title: Remote SP configuration
description: After you've set up a remote SP, configure it under Native Consoles > Access Management > Realms > Realm Name > Applications > Federation > Entity Providers > Provider Name.
component: pingoneaic
page_id: pingoneaic:am-saml2:saml2-remote-sp-configuration
canonical_url: https://docs.pingidentity.com/pingoneaic/am-saml2/saml2-remote-sp-configuration.html
llms_txt: https://docs.pingidentity.com/pingoneaic/llms.txt
docs_for_agents: https://developer.pingidentity.com/build-with-ai/docs-for-agents.md
section_ids:
  remote-sp-assertion-content: Assertion Content
  signing_and_encryption: Signing and Encryption
  nameid_format: NameID Format
  secrets: Secrets
  basic_authentication: Basic Authentication
  remote-sp-assertion-processing: Assertion Processing
  attribute_mapper: Attribute Mapper
  account_mapper: Account Mapper
  artifact_message_encoding: Artifact Message Encoding
  remote-sp-services: Services
  sp_service_attributes: SP Service Attributes
  remote-sp-advanced: Advanced settings
  request_processing: Request Processing
  sae_configuration: SAE Configuration
  idp_proxy: IDP Proxy
  config-treename: Tree Name
  application_context: Application Context
---

# Remote SP configuration

After you've set up a remote SP, configure it under Native Consoles > Access Management > Realms > *Realm Name* > Applications > Federation > Entity Providers > *Provider Name*.

## Assertion Content

The following properties appear under the Assertion Content tab:

### Signing and Encryption

* Request/Response Signing

  The requests and responses that the SP requires the IdP to sign digitally.

* Encryption

  The elements that the SP requires the IdP to encrypt.

  * Attribute Encryption – When selected, the IDP must encrypt SAML attributes.

  * Assertion Encryption – When selected, the IDP must encrypt SAML assertions.

  * NameID Encryption – When selected, IDP must encrypt NameID elements.

* Algorithms

  * Signing Algorithm – The signing algorithm the SP will use.

  * Digest Algorithm – The digest algorithm the SP will use.

  * Encryption Algorithm – The encryption algorithm the SP will use.

### NameID Format

* NameID Format List – The supported name identifiers for users who are shared between providers for single sign-on.

* NameID Value Map – Map the NameID format to a user profile attribute, for example:

  `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress=mail` or `urn:oasis:names:tc:SAML:2.0:nameid-format:persistent=objectGUID;binary`.

  * `Key` – The Name ID format to map, for example: `urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress`

  * `Value` – The profile attribute, for example: `mail`.

  * `Binary` – Indicates that the profile attribute is binary and should be Base64-encoded when used as the NameID value.

  If the specified NameID format is used in the protocol, the corresponding profile attribute value is used as the NameID in the Subject assertion element. This mapping overrides *all* the values defined in the NameID Value Map on the hosted IdP. For example, if a NameID Value Map is defined for the SP and a request is made with a specific NameID Format that only exists on the IdP, it will fail.

* Disable NameID Persistence Disables the storage of NameID values at the IdP when generating an assertion for this remote SP.

  Default value: `false`

### Secrets

* Secret Label Identifier – Identifier used to create a secret label for mapping to a secret in the secret store.

  Advanced Identity Cloud uses this label to create a specific secret label for this entity provider. The secret label takes the form `am.applications.federation.entity.providers.saml2.identifier.basicauth` where identifier is the value of Secret Label Identifier. The label can only contain characters `a-z`, `A-Z`, `0-9`, and periods (`.`). It can't start or end with a period.

  If you change the Secret Label Identifier for a specific entity provider, any corresponding mappings are deleted, unless they're referenced by other entity providers.

  |   |                                                                                                                                                                                                                                                                                |
  | - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
  |   | If you specify a value for Secret Label Identifier, and Advanced Identity Cloud finds a mapping to this secret label in the secret store, the value of the Password field is ignored. For basic authentication, there is no *default* secret label for the realm, or globally. |

### Basic Authentication

* Enabled – Require authentication with the specified username and password at SOAP endpoints.

* User Name – The username used to authenticate at SOAP endpoints.

* Password – The password used to authenticate at SOAP endpoints.

  |   |                                                                                                                                                                                                                                                                                |
  | - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
  |   | If you specify a value for Secret Label Identifier, and Advanced Identity Cloud finds a mapping to this secret label in the secret store, the value of the Password field is ignored. For basic authentication, there is no *default* secret label for the realm, or globally. |

## Assertion Processing

### Attribute Mapper

* Attribute Map

  Override mappings from assertion attributes to user profile attributes at the IdP.

### Account Mapper

* Name ID Mapper Script

  Script used for generating the NameID in SSO assertions. If a script is selected, it overrides the default `getNameID` method configured on the hosted IdP.

### Artifact Message Encoding

* Encoding

  The message encoding format for artifacts.

## Services

The following properties appear under the Services tab:

### SP Service Attributes

* Single Logout Service

  The endpoints to manage SLO depending on the SAML binding.

* Manage NameID Service

  The endpoints to manage NameIDs depending on the SAML binding.

* Assertion Consumer Service

  The endpoints to consume assertions, where the order corresponds to the index of the URL in the standard metadata.

## Advanced settings

### Request Processing

* Skip Endpoint Validation For Signed Requests

  When enabled, Advanced Identity Cloud doesn't verify assertion consumer service (ACS) URLs in SAML authentication requests. The ACS URL can contain dynamic query parameters, for example.

  The SAML 2.0 specification requires ACS URL verification. When you enable this, the SP must digitally sign the authentication request; in Assertion Content > Signing and Encryption > Request/Response Signing, enable Authentication Requests Signed. If Advanced Identity Cloud receives an unsigned authentication request, it returns an error.

### SAE Configuration

* SP URL

  The endpoint to manage SAE requests.

* SP Logout URL

  The SP endpoint to process global logout requests.

### IDP Proxy

* IDP Proxy enabled

  When enabled, authentication requests from the SP can be proxied.

* Proxy all requests

  When enabled, Advanced Identity Cloud proxies every authentication request from the SP, even if the `Scoping` element is missing.

  Set IDP Proxy enabled for this setting to take effect.

* Introduction enabled

  When enabled, use introductions to find the proxy IdP.

  This property requires a non-default *SAML2IDPProxyFRImpl* implementation.

* Use IDP Finder

  When enabled, Advanced Identity Cloud uses the IDP finder service to determine the proxy IDP.

* Proxy Count

  The maximum number of proxy identity providers. Advanced Identity Cloud sets the specified value in the `Scoping` element of proxied authentication requests.

  Enable Proxy all requests for this setting to take effect.

* IDP Proxy List

  A list of URIs for preferred proxy IdPs.

### Tree Name

* Tree Name

  If configured, Advanced Identity Cloud redirects the remote SP to the specified journey, ignoring the configured authentication context mapper and existing sessions. The redirect contains a transaction condition advice to ensure the journey is run.

  You can access the requested authentication context and configured mappings by including a [Scripted Decision node](https://docs.pingidentity.com/auth-node-ref/latest/scripted-decision.html) in the journey that queries the `samlApplication` script binding.

  |   |                                                                                                                                                                                                                                                                                                                                       |
  | - | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
  |   | To prevent users from authenticating directly through this journey, either for security reasons or because the journey is insufficient as a complete authentication service, configure it as a [transactional authentication journey](../am-authentication/configure-authentication-trees.html#configure-transactional-auth-journey). |

  Learn about SAML 2.0 application journeys in [Application journeys](../app-management/application-journeys.html).

### Application Context

* Application Context Enabled

  This setting controls the availability of the application context in SAML 2.0 flows through the `samlApplication` binding in [Scripted Decision node scripts](../am-scripting/scripting-api-node.html#samlapp-binding).

  Choose from the following options:

  * Default: Inherits the value from [`Enable Application Context`](saml2-hosted-idp-configuration.html#saml-idp-enable-app-context) in the hosted IdP configuration.

  * Enabled: The application context is always available.

  * Disabled: The application context is never available.
