Table of Contents

SAML 2.0 Integration

Last updated July 15, 2024

Access Anywhere supports integration with many directory services through the SAML and LDAP protocols providing authentication and authorization services including single-sign on, identity and group synchronization, auto-add and permission synchronization.

This document describes integration with SAML 2.0 using a number of popular providers. For LDAP see LDAP Integration and for Active Directory see Active Directory Integration. The Access Anywhere identity and access management features are summarized here.

The following flows are supported:

For specific details on configuring a specific identity provider follow a specific guides below:

Once you have completed the configuration you can use the Test Settings button, and complete this by clicking Add Auth System.

If you are looking for how to set up SAML integration with the SMB or Nasuni Connector please refer to this page.

Setting up SAML 2.0 with Access Anywhere

Enabling SAML in the Package

To begin configuring the SAML 2.0 connection, you will need to ensure that SAML is enabled in your Package. To do this login as the ApplAdmin user, visit the User Packages screen, find the package that your organization uses, and ensure that SAML 2 Login System is highlighted in the “Extra options” section

Configuring a SAML Authentication System

Next, login as the Organization Administrator, visit the Auth Systems screen from the Organization menu.

Under Add Auth System, select SAML from the dropdown beside Auth System.

On this screen, you are now required to enter details about your particular SAML 2.0 identity provider. The following list describes the meaning of each field, including one which will be populated automatically when the authentication system has been added.

Additional Options

Users Login Settings

SAML Users Import Fields

The Access Anywhere server requires certain pieces of information when mapping an authentication system user to a user. Since the names of the fields used by identity providers to hold these values are not standardized, you will need to supply the mappings.

SAML Users Import Settings

SCIM 2.0 - Server Configuration

As described here, Access Anywhere implements the SCIM 2.0 protocol, allowing identity providers to automatically provision users. If your SAML system supports SCIM and you wish to make use if it, set and use the details as described in this section.

If you have configured more than one SCIM-enabled authentication system and you are providing your own token values, be sure that they are unique.