MicroStrategy ONE
Configure MicroStrategy Identity as an Identity Provider in PingFederate
- In a web browser, log in to your PingFederate administrative console.
- Under SP Configuration, under IdP Connections, click Create New
- On the Connection Type page, select Browser SSO Profiles, then select SAML 2.0 from the Protocol drop-down list.
- On the Connection Options page, select Browser SSO.
- On the Import Metadata page, upload the Identity metadata that you downloaded from MicroStrategy Identity Manager.
- Click Next until you reach the Browser SSO page.
Configure Browser SSO
- On the SAML Profiles page, select SP-Initiated SSO.
- On the User-Session Creation page, click Configure User-Session Creation.
- Click Next until you reach the Adapter Mapping and User Lookup page.
- On the Adapter Mapping and User Lookup page, select Map New Adapter Instance.
- On the Adapter Instance page, select the adapter instance you want to use.
- On the Adapter Data Store page, select Use only the attributes available in the SSO Assertion.
- On the Adapter Contract Fulfillment page, for the subject Adapter Contract, select Assertion from the Source drop-down list and select SAML_SUBJECT from the Value drop-down list.
- Click Next.
- Click Done once you reach the Summary page.
- On the Browser SSO page, click Protocol Settings, then click Configure Protocol Settings.
- On the SSO Service URLs page, confirm that an Endpoint URL is defined. This value was provided when you uploaded the Identity metadata.
- On the SLO Service URLs page, confirm that an Endpoint URL is defined. This value was provided when you uploaded the Identity metadata.
- On the Allowable SAML Bindings page, select POST.
- On the Default Target URL page, leave the field blank.
- On the Signature Policy page, select Use SAML-standard signature requirements.
- On the Encryption Policy page, select None.
- Click Next.
- Click Done once you reach the Summary page.
IdP Connection Page
- On the IdP Connection page, click Credentials, then click Configure Credentials.
- On the Digital Signature Settings page, from the Signing Certificate drop-down list, select the certificate to use.
- Click Done.
- On the Activation and Summary page, select a Connection Status of Active.
- From the main PingFederate administrative console, under SP Configuration, under Application Integration Settings, click Default URLs.
- Specify the URL to redirect users to after signing in with MicroStrategy Identity, then save your changes.
Next, add users from your web application into MicroStrategy Identity.
