The following section describes the steps for configuring single sign-on (SSO) to Box. Configuring SAML SSO involves configuring both the PingFederate SP connection and Box.

Note: Configuring SSO is optional for outbound provisioning.
  1. Create a new SP connection or select an existing SP connection from the SP Configuration menu.
  2. On the Connection Template screen, select the Use a template for this connection option and choose Box Connector from the Connection Template drop-down list. You will be asked to provide the boxmetadata.xml file you obtained earlier in Download Box SAML 2.0 metadata file.
    An image of the Connection Template screen.
  3. On the Connection Type screen, ensure that the Browser SSO Profiles check box is selected.
  4. On the General Info screen, the default values are taken from the metadata file you selected in step 2. We recommend using the metadata default values.
    An image of the General Info screen.
  5. Click Next to continue the Browser SSO configuration. For more information, see the following sections under Identity provider SSO configuration:
  6. On the authentication adapter's Attribute Contract Fulfillment screen, map SAML_SUBJECT to email address.
  7. On the Protocol Settings > Allowable SAML Bindings screen, ensure that both POST and SOAP are selected.
  8. On the Credentials screen, click Configure Credentials.
  9. On the Back-Channel Authentication screen, click Configure.
  10. On the Inbound Authentication Type screen, select Digital Signature (Browser SSO profile only) and click Done.
  11. On the Credentials > Digital Signature Settings screen, select the signing certificate.
  12. On the Signature Verification Settings screen, click Manage Signature Verification Settings.
  13. On the Trust Model screen, ensure Unanchored is selected and click Next.
  14. On the Signature Verification Certificate screen, select the Box certificate as the primary certificate and click Next.
    An image of the Box Signature Verification Certificate.
  15. On the Activation & Summary screen, set Connection Status to Active, then click Save.