<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Umbrella SSO EntityID in Cloud Security</title>
    <link>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198162#M2013</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am configuring SAML SSO in Umbrella portal.&lt;/P&gt;&lt;P&gt;In the portal the metadata to add to my IDP uses EntityID&amp;nbsp;"&lt;A href="https://login.umbrella.com/sso" target="_blank" rel="noopener"&gt;https://login.umbrella.com/sso&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;This works correctly when I test my SSO configuration.&lt;/P&gt;&lt;P&gt;But when I update my IDP to use the&amp;nbsp;Umbrella metadata URL&amp;nbsp;&lt;A href="https://api.umbrella.com/admin/v2/samlsp/certificates/Cisco_Umbrella_SP_Metadata.xml" target="_blank" rel="noopener"&gt;https://api.umbrella.com/admin/v2/samlsp/certificates/Cisco_Umbrella_SP_Metadata.xml&lt;/A&gt;&amp;nbsp;the EntityID in that metadata is&amp;nbsp;"saml.gateway.id.swg.umbrella.com" and SSO breaks after an update.&lt;/P&gt;&lt;P&gt;Running a SAML trace I can see in the samlp AuthRequest that the&amp;nbsp;&lt;SPAN&gt;AssertionConsumerServiceURL is&amp;nbsp;"&lt;A href="https://login.umbrella.com/sso" target="_blank" rel="noopener"&gt;https://login.umbrella.com/sso&lt;/A&gt;" which does not match the EntityID in the metadata URL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Has anyone gotten SSO to work correctly when using the&amp;nbsp;&lt;SPAN&gt;Umbrella Fixed Metadata URL?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.umbrella.com/umbrella-user-guide/docs/saml-certificate-renewal-options" target="_blank" rel="noopener"&gt;https://docs.umbrella.com/umbrella-user-guide/docs/saml-certificate-renewal-options&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2024 14:01:35 GMT</pubDate>
    <dc:creator>nickp214</dc:creator>
    <dc:date>2024-09-24T14:01:35Z</dc:date>
    <item>
      <title>Umbrella SSO EntityID</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198162#M2013</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am configuring SAML SSO in Umbrella portal.&lt;/P&gt;&lt;P&gt;In the portal the metadata to add to my IDP uses EntityID&amp;nbsp;"&lt;A href="https://login.umbrella.com/sso" target="_blank" rel="noopener"&gt;https://login.umbrella.com/sso&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;This works correctly when I test my SSO configuration.&lt;/P&gt;&lt;P&gt;But when I update my IDP to use the&amp;nbsp;Umbrella metadata URL&amp;nbsp;&lt;A href="https://api.umbrella.com/admin/v2/samlsp/certificates/Cisco_Umbrella_SP_Metadata.xml" target="_blank" rel="noopener"&gt;https://api.umbrella.com/admin/v2/samlsp/certificates/Cisco_Umbrella_SP_Metadata.xml&lt;/A&gt;&amp;nbsp;the EntityID in that metadata is&amp;nbsp;"saml.gateway.id.swg.umbrella.com" and SSO breaks after an update.&lt;/P&gt;&lt;P&gt;Running a SAML trace I can see in the samlp AuthRequest that the&amp;nbsp;&lt;SPAN&gt;AssertionConsumerServiceURL is&amp;nbsp;"&lt;A href="https://login.umbrella.com/sso" target="_blank" rel="noopener"&gt;https://login.umbrella.com/sso&lt;/A&gt;" which does not match the EntityID in the metadata URL.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Has anyone gotten SSO to work correctly when using the&amp;nbsp;&lt;SPAN&gt;Umbrella Fixed Metadata URL?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.umbrella.com/umbrella-user-guide/docs/saml-certificate-renewal-options" target="_blank" rel="noopener"&gt;https://docs.umbrella.com/umbrella-user-guide/docs/saml-certificate-renewal-options&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 14:01:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198162#M2013</guid>
      <dc:creator>nickp214</dc:creator>
      <dc:date>2024-09-24T14:01:35Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella SSO EntityID</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198187#M2014</link>
      <description>SSO for users? Or just the management?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Sep 2024 14:36:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198187#M2014</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-09-24T14:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Umbrella SSO EntityID</title>
      <link>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198189#M2015</link>
      <description>&lt;P&gt;Just Management&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 14:37:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cloud-security/umbrella-sso-entityid/m-p/5198189#M2015</guid>
      <dc:creator>nickp214</dc:creator>
      <dc:date>2024-09-24T14:37:56Z</dc:date>
    </item>
  </channel>
</rss>

