Guidelines for SSO configuration on Cloud-Delivered Firewall Management Center
Restrictions for SSO provider configuration
The Cloud-Delivered Firewall Management Center can support SSO with only one SSO provider at a time. You cannot configure the Cloud-Delivered Firewall Management Center to use multiple SSO providers, such as both Okta and OneLogin, simultaneously.
SSO configuration in high availability deployments
Cloud-Delivered Firewall Management CenterCloud-Delivered Firewall Management Centers in a high availability configuration can support SSO, but you must address several considerations.
-
SSO configuration does not synchronize between members of a high availability pair. Configure SSO separately for each member.
-
Both Cloud-Delivered Firewall Management Centers in a high availability pair must use the same IdP for SSO. Configure a service provider application at the IdP for each Cloud-Delivered Firewall Management Center configured for SSO.
-
Before a user can use SSO to access the secondary Cloud-Delivered Firewall Management Center for the first time, the user must first use SSO to log into the primary Cloud-Delivered Firewall Management Center at least once.
-
When configuring SSO for Cloud-Delivered Firewall Management Centers in a high availability pair:
-
If you configure SSO on the primary Cloud-Delivered Firewall Management Center, you do not need to configure SSO on the secondary Cloud-Delivered Firewall Management Center.
-
If you configure SSO on the secondary Cloud-Delivered Firewall Management Center, you are required to configure SSO on the primary Cloud-Delivered Firewall Management Center as well. SSO users must log into the primary Cloud-Delivered Firewall Management Center at least once before logging into the secondary Cloud-Delivered Firewall Management Center.
-
SSO configuration in multi-tenancy environments
In a Cloud-Delivered Firewall Management Center that uses multi-tenancy, the SSO configuration can be applied only at the global domain level. That configuration applies to the global domain and all subdomains.
SSO configuration permissions and limitations
-
Only users with the Admin role authenticated internally or by LDAP or RADIUS can configure SSO.
-
The Cloud-Delivered Firewall Management Center does not support SSO initiated from the IdP.
-
The Cloud-Delivered Firewall Management Center does not support logging in with CAC credentials for SSO accounts.
-
Do not configure SSO in deployments using CC mode.
-
View SSO activity in the Cloud-Delivered Firewall Management Center audit log. The Subsystem field shows whether an activity was Login or Logout.