Step 1: Configure service provider - identity_federation - Latest

Precisely Identity Federation Guide

Product type
Software
Portfolio
notrequired_portfolio
Product family
Product
Precisely Identity Federation
Version
Latest
ft:locale
en-US
Product name
Precisely Identity Federation
ft:title
Precisely Identity Federation Guide
Copyright
2024
First publish date
2024
ft:lastEdition
2026-04-15
ft:lastPublication
2026-04-15T15:05:29.095000
L1_Product_Gateway
L2_Product_Segment
L3_Product_Brand
L4_Investment_Segment
L5_Product_Group
L6_Product_Name

This step defines the configuration on the Precisely side so Precisely’s applications can integrate with your IdP.

IdP’s that support SAML 2.0 should have a feature to export a SAML metadata file. If this is not available, or you prefer to configure the service provider options manually, complete each section of the form.
  1. In order to export a SAML file, your IdP may require URLs for Assertion Consumer URL/Single Sign-on URL and Audience URI/SP-Entity-Id. Enter placeholder values for now. Later in the process, this information will be replaced with the actual values.
  2. In the SAML metadata section, upload or paste a SAML metadata file exported from your Identity Provider (IdP). This will automatically populate the IDP Configuration section (Single Sign-On URL, Issuer URI, and Certificate).
  3. Within IDP Configuration, specify the Email Domain users will be signing in with. For example, if your users have email addresses (usernames) like myuser@mydomain.com, enter mydomain.com.
    Note: Use urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress as the format for the Subject NameId attribute to avoid an error during the authentication request.
    • By default, the domain you are currently signed in with automatically populates My email domain.

    • If you need to specify a different domain, select Alternate domain.

  4. In the Claims Mapping section, enter the SAML attribute claim name as defined in your Identity Provider's SAML application.

    Use the attribute name itself, not its value. Claim names are in URI format. For example: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

    Depending on your Identity Provider’s configuration, claim names may also be simple strings.

    The following fields are required: First name, Last name, and Email. The Federated groups field is optional.
    If the dropdown is populated, select a value and map each Source Field to the corresponding required Destination Field. If the claims attribute is not defined in your SAML metadata XML, manually enter the attribute name in the dropdown field.
  5. Click Next.