Configure a single sign-on (SSO) policy in Secure Access Service Edge (SASE) to authenticate users through the SASE identity provider (IdP) when they access your application portal.
Prerequisites
Before you begin, ensure that you have:
The redirect URL of your office application
Create a policy
Log on to the SASE console.
In the left-side navigation pane, choose Identity Authentication and Management > Single Sign-on.
On the Single Sign-on page, click Create Policy.
In the Create Policy panel, configure the following parameters.
Parameter Description Policy Name The name of the policy. Must be 2–100 characters and can contain letters, digits, hyphens (-), and underscores (_). Policy Status The status of the policy. Set to Enabled to activate the policy, or Disabled to deactivate it temporarily. ImportantDisabling the policy causes SSO to fail. Proceed with caution.
API access authorization The client_idandclient_secretvalues for API authorization. You must enable API access before SSO can work.ImportantKeep the client secret confidential. If it is leaked, delete it and create a new one for rotation.
Redirect URL The redirect URL of your office application. Set this to the value of the redirect_uriparameter in your application's URL. SASE adds this URL to a whitelist and uses it to initiate logon requests after authentication.Application Configuration The application configuration information specified by the following parameters: Issuer, Discovery Endpoint, Authorization Endpoint, Token Endpoint, Public Key Endpoint, and UserInfo Endpoint. When you connect to an IdP, you must configure these parameters. Click OK.
The new policy appears in the policy list.
What's next
After creating an SSO policy, complete the required configuration in the IdP that your office application uses. The configuration varies based on the IdP that you use.
After the configuration is complete, users can log on to the SASE client to access office applications. For details on the SASE client, see Install and log on to the SASE client.
To control which users can access specific applications, use the private access feature. For details, see Add an office application to SASE.
Manage policies
| Operation | Steps |
|---|---|
| Modify a policy | Find the policy and click Edit in the Actions column. View or update the configuration in the Edit panel. |
| Delete a policy | Find the policy and click Delete in the Actions column. Important Deleting a policy prevents users from accessing office applications. Proceed with caution. |