This topic tells you how to add an external identity provider to your Single Sign‑On for VMware Tanzu service plan.
Setting up SAML
-
Log in to the SSO Operator Dashboard at
https://p-identity.SYSTEM-DOMAIN
as a Plan Administrator. -
Select your plan and click Manage Identity Providers on the dropdown.
-
Click New Identity Provider to create a new identity provider.
-
To create a new identity provider, perform the following steps:
- Enter an identity provider name into Identity Provider Name.
- (Optional) Enter a description into Identity Provider Description.
-
Specify Identity Provider Metadata from step 11 of the Configure Okta as an Identity Provider topic.
- Option 1: Enter your Input Identity Provider Metadata URL and Fetch Metadata to fetch your identity provider metadata from an endpoint.
- Option 2: Click SAML File Metadata (optional) to upload your metadata XML manually.
-
(Optional) Under Advanced SAML Settings, click Attribute Mappings to enter the mappings.
-
Click Create Identity Provider.
-
Click Resource Permissions.
-
Click New Permissions Mapping and perform the following steps:
- Enter a Group Name.
- For Select Permissions, select the permissions that the members of the group from the external identity provider should have access to.
-
Navigate to the identity provider list.
-
Click Group Whitelist and enter the group names from the external identity provider that should be propagated in the ID token.
Content feedback and comments