Guidelines for SSO configuration on Cloud-Delivered Firewall Management Center

Restrictions for SSO provider configuration

The Cloud-Delivered Firewall Management Center can support SSO with only one SSO provider at a time. You cannot configure the Cloud-Delivered Firewall Management Center to use multiple SSO providers, such as both Okta and OneLogin, simultaneously.

SSO configuration in high availability deployments

Cloud-Delivered Firewall Management CenterCloud-Delivered Firewall Management Centers in a high availability configuration can support SSO, but you must address several considerations.

  • SSO configuration does not synchronize between members of a high availability pair. Configure SSO separately for each member.

  • Both Cloud-Delivered Firewall Management Centers in a high availability pair must use the same IdP for SSO. Configure a service provider application at the IdP for each Cloud-Delivered Firewall Management Center configured for SSO.

  • Before a user can use SSO to access the secondary Cloud-Delivered Firewall Management Center for the first time, the user must first use SSO to log into the primary Cloud-Delivered Firewall Management Center at least once.

  • When configuring SSO for Cloud-Delivered Firewall Management Centers in a high availability pair:

    • If you configure SSO on the primary Cloud-Delivered Firewall Management Center, you do not need to configure SSO on the secondary Cloud-Delivered Firewall Management Center.

    • If you configure SSO on the secondary Cloud-Delivered Firewall Management Center, you are required to configure SSO on the primary Cloud-Delivered Firewall Management Center as well. SSO users must log into the primary Cloud-Delivered Firewall Management Center at least once before logging into the secondary Cloud-Delivered Firewall Management Center.

SSO configuration in multi-tenancy environments

In a Cloud-Delivered Firewall Management Center that uses multi-tenancy, the SSO configuration can be applied only at the global domain level. That configuration applies to the global domain and all subdomains.

SSO configuration permissions and limitations

  • Only users with the Admin role authenticated internally or by LDAP or RADIUS can configure SSO.

  • The Cloud-Delivered Firewall Management Center does not support SSO initiated from the IdP.

  • The Cloud-Delivered Firewall Management Center does not support logging in with CAC credentials for SSO accounts.

  • Do not configure SSO in deployments using CC mode.

  • View SSO activity in the Cloud-Delivered Firewall Management Center audit log. The Subsystem field shows whether an activity was Login or Logout.