Affected Products:
- VMware Carbon Black Cloud
SSO can be enabled within the Carbon Black Cloud console to allow administrators to sign on through existing Azure AD configurations.
VMware Carbon Black Cloud leverages a service provider (SP) initiated login for SSO. Before starting SSO configuration, ensure that you have access to Azure as an Application Administrator, and VMware Carbon Black Cloud as a System Administrator or an administrator with permissions to modify the SAML configuration.
- Log in to your Azure portal at https://portal.azure.com using an account that has Application Administrator or higher privileges.
- Go to Enterprise applications by searching within the top bar.
- On the Enterprise Applications screen click All applications from the left Manage menu, then click the New Application option.
- Select the Create your own application option.
- In the Create your own application pane provide a name for the application, select the Integrate any other application that you don't find in the gallery (Non-gallery) radio button, then click Create.
Note: This may take several moments to create.
- From the application you created, select Single sign-on from the left Manage menu.
- Within the Select a single sign-on method pane, choose SAML as the single sign-on method.
- Click the Edit icon in the upper right of the Basic SAML Configuration section.
- Paste the Audience URL from the VMware Carbon Black Cloud console into the Identifier (Entity ID) field and set it as default.
- Paste the ACS (Consumer) URL from the VMware Carbon Black Cloud console into the Reply URL (Assertion Consumer Service URL) field and set it as default.
- Click the Save icon in the upper left of the Basic SAML Configuration pane.
- Click the Edit icon in the upper right of the User Attributes & Claims section.
- Click the three dots for the Additional Claims of
user.surname
, user.userprincipalname
, user.givenname
and delete those options. This leaves user.mail
as the only claim in the Additional Claims section.
- Click Unique User Identifier in the Required Claim section to modify the claim.
- Modify the Source Attribute from
user.userprincipalname
to user.mail
.
- Expand Choose name identifier format.
- Modify the Name identifier format to Default.
- Click the Save icon in the upper left.
- Select the Claim name under the Additional Claims heading.
- Modify the Name to mail.
Note:
- Not setting the Name results in
INVALID_ASSERTION
failures.
- Ensure that the Namespace is cleared. Any entries in this field results in
INVALID_ASSERTION
failures.
- Save the changes, then close the User Attributes & Claims pane.
- In the SAML Signing Certificate section, click Download next to the Certificate (Base64) option and save the certificate file. This is used when configuring the Carbon Black Cloud console.
- Copy the Login URL from the Set up <Application Name> section. This is used when configuring the Carbon Black Cloud console.
- Users must be added to the application to allow them to log in. Select Users and groups from the left Manage menu.
- Select the Add user/group option.
- Click None Selected to add a user.
- Assign the appropriate users and groups then click Select.
- Once the users that have been added, click Assign at the bottom left.
To contact support, reference Dell Data Security International Support Phone Numbers.
Go to TechDirect to generate a technical support request online.
For additional insights and resources, join the Dell Security Community Forum.