Configure Generic SAML SSO
If your SSO provider does not have a formal Rapid7 Digital Risk Protection (Threat Command) app, you can support SAML SSO authentication independently using a custom/local app.
In addition, you can enable SP-initiated SSO and also user provisioning with the SAML Just In Time (JIT) method.
Before configuring generic SSO:
- Generic SSO is supported only in IdP providers that support SAML 2.0 and that enable SAML claims (attributes) to specify the user Email address.
- This process is for advanced users who are very proficient in the setup and configuration of their SSO provider.
- If configurations are required that exceed what is described here, this generic option may not be suitable.
- Please contact your Customer Success Advisor or Customer Support to determine what help can be provided and if it is covered under your support agreement.
The following example demonstrates the necessary configuration to an enterprise app with Digital Risk Protection:
Follow these same guidelines with other SSO providers that support the SAML protocol. Terminology and parameter names may differ.
Ensure that you use DRP-registered user email address for the email and Unique User Identifier attributes.
For assistance, contact Rapid7 Support.
Configure Digital Risk Protection to accept sign-in from a generic SAML SSO
Before you begin, ensure that:
- You can access DRP as an administrator.
- You have created and downloaded the base 64 certificate from your SSO provider.
- (Optional) To enable SP-initiated login, you can provide the IDP URL and Issuer ID for the SSO provider.
To configure Digital Risk Protection to accept the generic SSO:
- Log in to the Command Platform as an administrator.
- From the Command Platform main menu, select Administration > Digital Risk Protection > Authentication.
- Enable SAML single-sign-on.
- For Provider name, select generic.
- Upload the certificate.
- (Optional) To enable SP-initiated login to DRP, perform the following:
- Select Enable SP-initiated login.
- Enter the IDP URL and Issuer ID. You can get this information from the SSO provider. For more information, see Enable SP-Initiated User Login.
- (Optional) In the Force logout**** section, set the maximum hours for a user session to remain valid. After this time period, the user must sign in through their SSO to regain access to DRP.
- Click Save changes.