KOP Integrations - ADFS - Rafay Product Documentation

ADFS

Follow the steps documented below to integrate your Org and ADFS (Active Directory Federation Services) for Single Sign On (SSO).

Important
Only users with "Organization Admin" privileges can configure SSO in the Web Console.


Step 1: Create IdP

Important
Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Important
Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org) can decrypt the SAML assertion.


Step 2: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your ADFS Relying Party Trust configuration. Provide the following information to your ADFS administrator.


Step 3: Specify IdP Metadata


Step 4: Verify Domain for IdP Integration


Step 5: Create Relying Party Trust in ADFS


Step 6: Add Claims For Relying Party Trust


Step 7: Groups Configuration In Web Console

Identical named groups with the Active Directory group names need to be created in your Org. Ensure that these groups are mapped to the appropriate Projects with the correct privileges. In the example below, the Group "OrgAdminUsers" is configured as an "Organization Admin" with access to all Projects.

It is important to emphasize that because of SSO via ADFS, user lifecycle management can be completely offloaded to the IdP. In the example below, note that there is no Local Users managed in the "OrgAdminUsers" group but there are IDP Users because they are all managed in ADFS.


Recap

Congratulations! You have successfully enabled SSO using ADFS. You should be able to login to the Web Console using your ADFS credentials.