This step defines the configuration on the Precisely side so Precisely’s applications can integrate with your IdP.
IdP’s that support SAML 2.0 should have a feature to export a SAML metadata file. If this is not available, or you prefer to configure the service provider options manually, complete each section of the form.
- In order to export a SAML file, your IdP may require URLs for Assertion Consumer URL/Single Sign-on URL and Audience URI/SP-Entity-Id. Enter placeholder values for now. Later in the process, this information will be replaced with the actual values.
- In the SAML metadata section, upload or paste a SAML metadata file exported from your Identity Provider (IdP). This will automatically populate the IDP Configuration section (Single Sign-On URL, Issuer URI, and Certificate).
-
Within IDP Configuration, specify the Email Domain users will be signing in with. For example, if your users have email addresses (usernames) like myuser@mydomain.com, enter
mydomain.com.Note: Use urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress as the format for the Subject NameId attribute to avoid an error during the authentication request.-
By default, the domain you are currently signed in with automatically populates My email domain.
-
If you need to specify a different domain, select Alternate domain.
-
-
In the Claims Mapping section, enter the SAML attribute claim name as defined in your Identity Provider's SAML application.
Use the attribute name itself, not its value. Claim names are in URI format. For example:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givennameDepending on your Identity Provider’s configuration, claim names may also be simple strings.
The following fields are required: First name, Last name, and Email. The Federated groups field is optional.If the dropdown is populated, select a value and map each Source Field to the corresponding required Destination Field. If the claims attribute is not defined in your SAML metadata XML, manually enter the attribute name in the dropdown field. - Click Next.