Authenticate remote access VPN users using SAML SSO
About SAML Single Sign-On authentication
Security Assertion Markup Language (SAML) is an open standard that enables single sign-on (SSO) across multiple applications by exchanging authentication and authorization data between an Identity Provider (IdP) and a Service Provider (SP).
When users authenticate with the IdP, it shares their identity with authorized applications (SPs). This action enables seamless access for users and permits centralized access control.
SAML SSO with Cloud-Delivered Firewall Management Center
Firewall Threat Defense supports SAML 2.0 SSO for remote access VPN connections using Secure Client. With SAML IdP integration, users sign in to Cloud-Delivered Firewall Management Center through the IdP and access resources based on their identity. The integration includes these components:
-
Identity Provider (IdP)—Performs user authentication, authorization, and issues assertions. For example, Duo, Microsoft Entra ID, and Okta.
-
Service Provider (SP)—Obtains the authentication assertion from IdP. A Firewall Threat Defense device acts as the SP.
-
Secure Client—Performs SAML 2.0 authentication using the embedded browser.