Before you begin configuring Microsoft Entra ID, make sure of the following:
- You are logged on the management console as DDI administrator.
- You have obtained the metadata file from DDI.
You can get it in the Deep Discovery Inspector management console going to Administration > Integrated Products/Services > SAML Authentication > Service Provider tab > Click Download Metadata.
Follow the instructions below to configure Microsoft Entra ID.
- Create a new application for DDI.
- Logon to Microsoft Entra ID portal, go to Home > Microsoft Entra ID.
- On the left navigation, click Enterprise applications.
- Create a new application by “Create your own application”.
- Specify a display name for Deep Discovery Inspector, for example, “Deep Discovery Inspector”.
- Select Integrate any other application you don't find in the gallery (Non-gallery) then click Create.
- Upload DDI meta file.
- Once the application is created, the main page of the application will show up. Click Single sign-on on the left navigation.
- Select SAML as the single sign-on method.
- On the Basic SAML Configuration section, upload the Deep Discovery Inspector metadata file by Upload metadata file and Save.
- Once the metadata file is successfully uploaded, the Identifier value gets auto populated in Basic SAML Configuration section textbox.
- Configure a group claim called DDI_GROUP.
- On the Attributes & Claims section, click Edit then select Add a group claim.
- For the associated group, it's recommended to select Groups assigned to the application to restrict the accessibility.
- For the Source attribute, choose sAMAccountName or Cloud-only group display names (It depends on its on-premise AD sourced or Microsoft Entra ID sourced).
Microsoft Entra ID may not supported to emit nested group name for group claims.
- In Advanced options, check the Customize the name of the group claim option and name it to “DDI_GROUP” and then Save.
- Make sure there is an additional claim called DDI_GROUP in the Attributes & Claims section.
- Assign a group to the application.
In the section Users and groups on the left navigations, add the group which is authorized to sign on to Deep Discovery Inspector.
- The application should be set up. Export the Identity Provider metadata by clicking the Download link for the Federation Metadata XML in the SAML Certificates section.
- Import Identity Provider information to DDI.
- Add SAML account.
The SAML Single Sign-On has been set up on DDI.Add SAML account following DDI Administrator's Guide > Chapter 6: Administration > Accounts > Adding a SAML Account.
