Many organizations use SAML to authenticate users for web services.
Prisma Cloud supports the SAML 2.0 federation protocol to access the Prisma Cloud Console.
When SAML support is enabled, users can log into Console with their federated credentials.
This article provides detailed steps for federating your Prisma Cloud Console with Google G Suite.
The Prisma Cloud/G Suite SAML federation flow works as follows:
Users browse to Prisma Cloud Console.
Their browsers are redirected to the G Suite SAML 2.0 endpoint.
They enter their credentials to authenticate.
Multi-factor authentication can be enforced at this step.
A SAML token is returned to Prisma Cloud Console.
Prisma Cloud Console validates the SAML token’s signature and associates the user to their Prisma Cloud account via user identity mapping or group membership.
Setting up Google G Suite
Prisma Cloud supports SAML integration with Google G Suite.
Log into your G Suite admin console.
Click on
Apps
.
Click on
SAML apps
.
Click the
+
button at the bottom to add a new app.
Click
SETUP MY OWN CUSTOM APP
at the bottom of the dialog.
Copy the
SSO URL
and
Entity ID
, and download the certificate.
You will need these later for setting up the integration in Prisma Cloud Console.
Click
NEXT
.
Enter an
Application Name
, such as
Prisma Cloud
, then click
NEXT
.
In the Service Provider Details dialog, enter the following details, then click
Paste the SSO URL, Entity ID, and certificate that you copied during the G Suite set up into the
Identity Provider single sign-on URL
,
Identity provider issuer
, and
X.509 certificate
fields.
Set
Audience
to match the application Entity ID configured in G Suite.
Enter
twistlock
.
Click
Save
.
Go to
Manage > Authentication > Users
, and click
Add user
.
In the
Username
field, enter the G Suite email address the user you want to add.
Select a role, then click
Save
.
Be sure
Create user in local Prisma Cloud account database
is
Off
.
Log out of Console.
You will be redirected into G Suite and you might need to enter your credentials.
After that, you will be redirected back into Prisma Cloud and authenticated as a user.