Skip to main content

Illumio Administration Guide 25.4

STEP 2: Configure SSO settings in Azure AD

Note

Only an Azure Application Administrator can configure Azure AD.

  1. In a different browser tab, log in to Azure AD as an Application Administrator.

  2. Go to Enterprise applications > All applications.

  3. Search for the Illumio SSO app and then click the app.

    azure-ad-search-illumio-sso.png
  4. In the center of the page under Getting Started, click Get started on the Set up single sign on tile.

    azure-ad-setup-sso.png
  5. If prompted to select a single sign-on method, click SAML.

  6. Configure Basic SAML:

    1. On the Set up Single-Sign On with SAML page Basic SAML Configuration tile, click Edit.

      azure-ad-basic-saml-config.png
    2. On the  Basic SAML Configuration  panel that opens, populate the fields with the values you copied and preserved.

      • In the Identifier (Entity ID) field, paste the Issuer URL you copied from the Illumio PCE.

      • In the Reply URL (Assertion source Service URL field, click Add reply URL and then paste the Assertion Source URL you copied from the Illumio PCE. Note: Your Reply URL must have a subdomain such as www, wd2, wd3, wd3-impl, wd5, wd5-impl. For example, http://www.myIllumio.com will work but http://myIllumio.com won't.

    3. Click Save and close the Basic SAML Configuration  panel.

  7. Click Edit on the Attributes & Claims tile.

    azure-ad-attributes-claims-config.png
  8. Under Required claim, update the Claim name:

    azure-ad-sso-update-claim-name.png
    1. Click the three dots.

    2. On the Manage claim page, click in the Source attribute field and select user.mail from the dropdown.

    3. Click Save.

  9. Back on the Attributes & Claims page, delete all of the existing claims in the Additional claims section by clicking the three dots for each one and then clicking Delete.

    azure-ad-delete-existing-claims.png
  10. Click Add new claim and add three new claims:

    azure-ad-sso-claims.png

    Given Name

    Surname

    User.MemberOf