Setting Up SSO for ZPC with ADFS
Â
Â
About SAML Single Sign-On in ZPC
Single Sign-On can be setup in ZPC against any Identity Provider (IdP) which supports SAML 2.0.
This guide covers the steps required to setup SAML SSO against ADFS.
For an exhaustive list of supported IDPâs, visit SAML-based products and services.
Provide ZPC Service Provider (SP) Metadata to your Identity Provider (IdP)
Export the SP Metadata to provide to your IdP.
Â
Adding ZPC as a Service Provider (SP) in ADFS using metadata.xml file:
Click on Add Relying Party Trust
Â
Select default option âClaims Awareâ
Â
Select âImport data about the relying party from a fileâ
Â
Upload the Service Provider (SP) metadata file from previous step.
Provide a meaningful Display Name for ZPC relying party and click âNextâ
Â
Select âPermit everyoneâ and click âNextâ
Â
Enable âConfigure claims issuance policy for this applicationâ checkbox and click âCloseâ
Configure Name Identifier (NameID)
Edit Claim Issuance Policy
Â
Click âAdd Ruleâ
Â
Choose Claim rule template âSend LDAP Attributes as Claimsâ and click âNextâ
Â
Provide a Claim rule name, select the Attribute Store âActive Directoryâ from the dropdown, provide the value from Username Attribute from LDAP Management in ZPC to Name ID mapping and click âFinishâ.
Download your Identity Provider (IdP) Metadata
Drop this link in your browser to download your IdP metadata.
https://< hostname >/federationmetadata/2007-06/federationmetadata.xml
Go back into ZPC and complete the SAML SSO Configuration
Import your IDP metadata
Enable SSO
Logout from ZPC
Go to the ZPC URL & click the teal login button to authenticate using SAML SSO
For any login issues with SSO, please reach out to ZIRO Support.
Â
SSO Configuration Complete â
Once logged in you will have initiated a Single Sign-On session which will give you access to all other applications registered to your IdP server without having to re log-in.