Resolve supports IDP Initiated SAML 2.0 for authentication. To configure SAML, NetSPI will need the IDP Metadata XML file.
Okta
- Add an Okta SAML application
- General Information
- Callback URL: https://resolve.netspi.com/api-gateway/callback/saml2
- Audience URI (SP Entity ID): https://resolve.netspi.com
- Single Sign On URL: https://resolve.netspi.com/api-gateway/callback/saml2
- Recipient URL: https://resolve.netspi.com/api-gateway/callback/saml2
- Destination URL: https://resolve.netspi.com/api-gateway/callback/saml2
- Audience Restriction: https://resolve.netspi.com/api-gateway/callback/saml2
- Default Relay State: blank
- Name ID Format: EmailAddress
- Application Username: Okta Username
- Attribute Statements
- firstname: user.firstname
- lastname: user.lastname
- email: user.email
- Complete and finish app creation
- Send the metadata file to NetSPI to import.
Microsoft Azure Active Directory
- Within Azure->Azure Active Directory, add an Enterprise Application
- Go to Set up single sign on
- General Information
- Identifier (Entity ID): resolvedevsso
- Reply URL (Assertion Consumer Service URL): https://resolve.netspi.com/api-gateway/callback/saml2
- User Attributes & Claims:
- lastname: user.surname
- firstname: user.givenname
- email: user.othermail (or user.mail)
- name: user.otheremail, user.userprincipalname, or user.mail
- Unique User Identifier: user.othermail (or user.mail)
- Download Federation Metadata XML by clicking Download on the application
- Navigate to Administration > Authentication > SAML in Resolve and add a new IDP, supplying the downloaded file
Google Workspaces
- Within admin.google.com->Apps->Web and Mobile Apps
- Add App->Add custom SAML app
- App name -> Relevant application name (NetSPI Resolve)
- Description -> Login to NetSPI Resolve
- App icon:
- Click on DOWNLOAD METADATA (the xml file downloaded will be sent to NetSPI)
- Service provider details
- ACS URL: https://resolve.netspi.com/api-gateway/callback/saml2
- Entity ID: NetSPI Resolve
- Name ID format: EMAIL
- Name ID: Basic Information > Primary email
- Attributes:
- Primary email -> email
- First name -> firstname
- Last name -> lastname
- Phone number -> phone