In CDP, you must create an identity provider to capture the SAML metadata and connection information for your enterprise IdP. To create an identity provider in CDP, you must be a CDP account administrator or have the PowerUser role.
Required role: Account administrator or PowerUser
Sign in to the CDP console.
From the CDP home page, click Management Console.
In the Management Console home page, navigate to Administration
and select the Authentication tab.
Configure the following settings for SAML:
In IDP Metadata, select File Upload to
upload a file that contains the identity provider SAML metadata or select
Direct Input to paste the identity provider SAML metadata
directly.
To synchronize the groups, select the Sync Groups on Login
option.
If you want to generate workload usernames by email, select its associated
option.
If your LDAP is not configured, please ensure you fill in your LDAP configurations as
they are required by CDP Data Services for workload authorization.
Click Update Authentication Settings.
To set up SAML as the preferred identity provider, go to the Preferred
Authentication Type section, select SAML and click
Save. If you are switching your preferred authentication type
from LDAP to SAML OR SAML to LDAP, ensure you migrate your users. For more information
see, Migrating users from another preferred identity provider
Once you update your authentication settings, the
Authentication Page will have your new identity provider (IDP)
information. It will reflect your previously saved configurations and also provide the CDP
SAML Service Provider Metadata. This will be used to configure your IDP.
These are the properties for your SAML identity provider:
Property
Description
SAML Identity Provider Metadata
The identity provider SAML metadata for your enterprise IdP that you provided
when you created the CDP identity provider.
Sync Groups on Login
Indicates whether CDP synchronizes a user's group membership in CDP with the
user's group membership in your enterprise IdP when a user logs in.
For more
information about user group synchronization, see Group Membership
Synchronization.
Generate workload username by email
You can optionally check this if you want the workload username to be generated
based on the email instead of the default.
CDP SAML Service Provider Metadata
The CDP SAML service provider metadata to configure your enterprise
IdP.