Use Vantage as the IdP for a group

Learn how you can use Security Assertion Markup Language (SAML) and Vantage as Identity Provider (IdP) to authenticate your sensors.

To enable your sensors to be able to use Vantage to log in, you need to propagate the groups to all those sensors for which you want to enable single sign-on (SSO). The correct security assertion markup language (SAML) configuration will be also be propagated to the sensors.

Metadata XML

Each sensor has its own SAML metadata file, which is located at <VANTAGE_URL>/api/v1/idp/<SENSOR_ID>/saml/metadata
Note:
Only admin users can access the SAML metadata resource.

Sensor URL

The Sensor URL is a sensor setting which represents the uniform resource locator (URL) of the sensor that the browser accesses. It is used for the SAML response callback.

To edit the Sensor URL, open the details page for the applicable sensor and go to Settings > Sensor URL.

Figure 1. Sensor URL field

Sensor URL field

Note:
When a sensor is connected to Vantage, and a valid Nozomi URL has been previously set, it automatically sends its Nozomi URL. When Sensor URL is modified in Vantage, it will be propagated to the sensor, and will overwrite the existing Nozomi URL.

Use cases

Guardian(s) connected directly to Vantage, with no Central Management Console (CMC)s: No action is required.

Guardian(s) attached to a CMC, which is attached to Vantage:

  • If configuration is pushed on Guardians, the Go to sensor feature on the CMC using SSO will not work. (The Go to sensor feature on the CMC with local user will continue to work.) It is recommended that you:
    • Only push groups to the CMC that is directly attached to Vantage
    • Continue to manage the SSO to the Guardian from this CMC
  • If Go to sensor feature on the CMC using SSO is not used, no action is required.