All pages
Powered by GitBook
1 of 1

Loading...

Configuration

In this article you will learn how to configure your Xopero ONE login with SAML.

SAML provides secure single sign-on by integrating an identity provider (IdP) with Xopero ONE, allowing users to authenticate with centralized credentials while ensuring controlled access and compliance.


Overview

Xopero ONE integration works via the SAML 2.0 protocol, meaning any platform supporting this protocol can be integrated with Xopero ONE.

The configuration process is straightforward and requires only the entity ID, metadata URL, reply URL, and logout URL (the names may vary depending on the naming conventions used by specific platforms). In some cases, a certificate and a private key are also required.


Configuration

Do not test the integration in the IdP panel (for example, the Azure Portal) as it will initiate login from the IdP panel.

Below table illustrates SAML integration configuration for selected platforms, including Auth0, Entra ID, CyberArk, Google, JumpCloud, Okta, and OneLogin.

circle-1Configuration in Auth0 circle-2Configuration in Xopero ONE

Configuration in Auth0

  1. Open your Auth0 admin dashboard, go to Dashboard > Applications > Applications, and hit Create Application button in the top-right corner of the screen.

  1. In Create application window enter a unique, custom application name (in this example we'll be using XoperoAuth0), select Regular Web Applications option, and click Create:

  1. In the newly created application window go to Settings tab, scroll down to the very bottom, and click Advanced Settings collapsible to expand it.

  1. Go to the Endpoints tab and locate SAML section. Copy the SAML Metadata URL and save it for later — it will be needed for Xopero ONE configuration.

  1. Scroll back to top and open the Addons tab, then toggle the SAML2 WEB APP button.

  1. In the window that opens up open the Settings tab and enter the Application Callback URL as follows:

https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

  1. In the same tab, scroll down inside the code input field and uncomment 31st, 32nd and 33rd line, then edit line 32 as follows:

  1. Once done, scroll down to the bottom of the addon window and click Enable button, then close the window to finish app configuration.


  1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

  1. Click Add new provider button and fill in the details:

Name: your own custom name, i.e., Auth0

Entity ID: should be the same name you've set as application name in Auth0 (in this example it's XoperoAuth0)

  1. Next, paste the previously copied SAML Metadata URL in the Metadata URL field.

  1. Add certificate and password if required.

  2. Set up a default Language and Role for users with Auth0 SAML authentication permissions.

  3. Double-check the settings and hit Save at the bottom of Add identity provider tab.

  1. Login to , select Microsoft Entra ID and click Manage > Enterprise applications.

  2. Click the New application button and then Create your own application.

  3. Enter a custom name for the app and select Integrate any other application you don’t find in the gallery (Non-gallery).

  1. Log in to your CyberArk account. Expand Apps & Widgets dropdown menu and select Web Apps.

  2. Click Add Web Apps button in the top-right corner.

  1. Go to Custom

  1. Login to your Google admin console. Next, click the burger menu icon in the top-left corner of the screen and go to Apps > Web and mobile apps. Click Add app and select Add custom SAML app from the drop-down menu.

  1. In the app details page create a custom name for your app and type it in App name field, then click Continue.

  1. Log in to the JumpCloud Admin Portal, navigate to USER AUTHENTICATION > SSO Applications, and then click + Add New Application.

  2. In Create New Application Integration window search for Custom Application, select it, and hit Next.

PKCS #12 file with X.509 certificate and private key (usually a .pfx file; can be password protected) must be included in IdP configuration in Xopero ONE. X.509 certificate file (usually a .crt file) for signature verification on IdP side must be included in application configuration defined in Okta panel.

Both files contain the same certificate. The PKCS #12 file also contains a private key to this certificate.


  1. In Admin dashboard (in the right-top corner of the window) expand the Applications tab and select the Applications option.

  1. Login to your OneLogin admin console and go to Applications > Applications > Add App.

  2. Search for SAML Custom Connector (Advanced) and select the first result from the search results.

  3. Next, enter a unique, custom name for the app in Display Name field and hit Save


To log in to Xopero ONE using a SAML-integrated identity provider, always start from the Xopero ONE panel. Do not log in from the IdP panel (for example, the Okta panel) to the application configured for Xopero ONE — the only exception is JumpCloud, which provides a built-in option to log in directly from its panel.

To enable an existing Xopero ONE user to log in via an identity provider (IdP), you must turn on the IdP login toggle for that account (⚙️ Settings > Accounts > Edit). Once an account is set to use an identity provider (IdP) for authentication, it cannot be switched back. To change the authentication method, you must delete the account and add it again.

Click Save to finish the setup. You can now log out and test your configured SAML login integration.
  1. Confirm the configuration and click Create button.

  2. Open the Single sign-on tab and select SAML method.

  1. Click the Edit button in Basic SAML Configuration section to edit it.

  1. Set up a unique Identifier (Entity ID) i.e., SAMLTestAzure

  2. Enter the following URL in Reply URL (Assertion Consumer Service URL) section:

https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

  1. Change the Logout Url (Optional) to the following address:

https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse

  1. Double-check if the info you have entered is correct and click the Save button.

  2. Next, click the Edit button in Attributes & Claims section and click + Add a group claim button.

  1. Select All groups and go to Advanced options. Check the Filter group box and fill in the fields as follows:

Attribute to match: Display name Match with: Prefix String: XONE

  1. Check the Customize the name of the group claim checkbox. Enter xoperogroup in the Name field and save your settings.

  1. Go back to SAML-based Sign-on page and copy the App Federation Metadata Url.

  2. Save your settings.

  3. Open the Users and groups tab and click + Add user/group button. Select users you want to be able to login to Xopero ONE and save your settings.


  1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

  1. Click Add new provider button and fill in the details:

Name: your own custom name, i.e., Entra ID

Entity ID: should be the same name you've set in Identifier (Entity ID) in Azure Portal (in this example it's SAMLTestAzure)

  1. Next, paste the previously copied App Federation Metadata Url in the Metadata URL field.

  1. Add certificate and password if required.

  2. Set up a default Language and Role for users with Entra ID SAML authentication permissions.

  3. Double-check the settings and click Save at the bottom of Add identity provider tab.

  4. Click Save to finish the setup. You can now log out and test your configured SAML login integration.

tab, find
SAML
on the list, and click the
Add
button next to it.
  1. Confirm adding SAML as a web app.

  1. You’ll be redirected to SAML web app settings. Start with setting up a custom name for the app (i.e., XONESAML).

  1. Next, set up a unique Application ID in Advanced section and Save your settings (in this example we will be using XONESAMLID).

  1. Open the Trust tab and copy Metadata URL in Identity Provider Configuration section (it will be needed later for Xopero ONE configuration).

  1. Next, scroll down to Service Provider Configuration section, set it to Manual Configuration, and enter the following data:

In SP Entity ID / Issuer / Audience type your previously defined Application ID (in this example it is XONESAMLID)

In Assertion Consumer Service (ACS) URL enter:

https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

In Single Logout URL enter:

https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse

Manual configuration overview.
  1. Go to SAML Response tab and scroll down to Script to set custom claims section. Enter the following script and press the Save button:

  1. Head over to Permissions tab, click Add button, select all users you want to authorize to use SAML integration, and Save your settings.


  1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

  1. Click Add new provider button and fill in the details:

Name: your own custom name, i.e., CyberArk

Entity ID: should be the same name you've set in Application ID in CyberArk (in this example it's XONESAMLID)

  1. Next, paste the previously copied Metadata URL in the Metadata URL field.

  1. Add certificate and password if required.

  2. Set up a default Language and Role for the users with CyberArk SAML authentication permissions.

  3. Click Save to finish the setup. You can now log out and test your configured SAML login integration.

XMS login page with CyberArk SAML integrity set up.
  • Next, click DOWNLOAD METADATA button under Option 1: Download IdP metadata. Upload the downloaded file to your web server and save its URL (it will be needed later for Xopero ONE configuration).

    1. Click Continue and in the next window screen fill the Service provider details as follows:

    ACS URL:

    https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

    Entity ID: custom, globally unique name (in this example we'll be using SAMLGOOGLE)

    Start URL (optional): your XoperoONEManagementServiceURL

    1. Once done, click Continue and on the next page hit Finish.

    2. Back on the admin console main page, click the burger menu in the top-left corner, go to Apps > Web and mobile apps, then select your newly created SAML app.

    3. Click User access and select either On for everyone or Off for everyone based on your organization's needs.

    1. Once done, hit Save to finish the configuration process.


    1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

    1. Click Add new provider button and fill in the details:

    Name: your own custom name, i.e., Google

    Entity ID: should be the same name you've set in Google (in this example it's SAMLGOOGLE)

    1. Next, paste the previously copied metadata URL in the Metadata URL field.

    1. Add certificate and password if required.

    2. Set up a default Language and Role for the users with Google SAML authentication permissions.

    3. Click Save to finish the setup. You can now log out and test your configured SAML login integration.

    Check Manage Single Sign-On (SSO) checkbox and select Configure SSO with SAML option., then hit Next.

    1. In Enter general info set a unique custom application name (in this example we'll be using XONE), type it in Display Label field, and click Save Application.

    1. In your new application settings go to SSO tab and fill the fields as follows:

    IdP Entity ID: your unique application name (in this example it's XONE)

    SP Entity ID: your unique application name (in this example it's XONE)

    1. Click the Copy Metadata URL button under JumpCloud Metadata at the top and save it for later— it will be needed for Xopero ONE configuration in XMS.

    2. Scroll down, set SAMLSubject NameID to email, and for SAML Subject NameID Format select urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress from the drop down menu.

    1. In Sign section select Assertion. The IDP URL should read:

    https://sso.jumpcloud.com/saml2/xone

    Correctly filled Login URL example.
    1. In Attributes section add a new logout response by filling the fields as follows:

    Service Provider Attribute Name:

    https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse

    JumpCloud Attribute Name: select email from the drop-down menu

    1. Click Save to update the connector and move to the User Groups tab. Select the groups/users you want to enable JumpCloud SAML authorization for Xopero ONE login to.

    1. Double-check if the data you entered is correct and save your configuration.


    1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

    2. Click Add new provider button and fill in the details:

    Name: your own custom name, i.e., JumpCloud

    Entity ID: should be the same name you've set in SSO IDP Entity ID in JumpCloud (in this example it's XONE)

    1. Next, paste the previously copied Metadata URL in the Metadata URL field.

    2. Add certificate and password if required.

    3. Set up a default Language and Role for the users with JumpCloud SAML authentication permissions.

    4. Click Save to finish the setup. You can now log out and test your configured SAML login integration.

    1. Hit Create App Integration button and select SAML 2.0.

    1. In General Settings enter a unique application name and move to Configure SAML section.

    1. In Configure SAML tab set the Single sign-on URL parameter as follows:

    https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

    1. In Audience URL type your unique application name that you've previously set in General Settings tab.

    2. Click Show advanced settings and upload the certificate file to Signature Certificate field. Check Allow application to initiate Single Logout checkbox in the Enable Single Logout section— it's necessary.

    3. You will now see two additional fields under Enable Single Logout— fill them as follows:

    Single Logout URL:

    https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse

    SP Issuer: your unique application name that you've previously set in General Settings tab (in this example it's MyOktaApp)

    1. Next, go to Group Attribute Statements section and fill it as follows:

    Name: xoperogroup

    Starts with: XONE

    1. Double-check if the data you've entered is correct and click Next. In the next window select I'm an Okta customer adding an internal app option, then hit Finish.

    2. Open the created application and go to Sign On tab.

    1. In SAML Signing Certificates section select your uploaded certificate and click Actions > View IdP metadata. Copy the URL of the opened page— it will be required later in Xopero ONE configuration.

    2. Once done, go to the Assignments tab.

    Assignments tab view.
    1. Assign the application to a selected user, or group. Hit Done to finish the configuration.


    1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

    1. Click Add new provider button and fill in the details:

    Name: your own custom name, i.e., Okta

    Entity ID: should be the same name you've set in General Settings in Okta (in this example it's MyOktaApp)

    1. Next, paste the previously copied IdP metadata URL in the Metadata URL field.

    1. Add the required certificate and a password to the Password Manager.

    1. Set up a default Language and Role for the users with Okta SAML authentication permissions.

    1. Click Save to finish the setup. You can now log out and test your configured SAML login integration.

    .
  • Open the Configuration settings of your custom app, fill the displayed fields as follows and hit Save to save the configuration:

  • Audience (EntityID): a unique, custom name to identify the app on the IdP side (in this example we'll be using XOPEROSAML)

    ACS (Consumer) URL Validator*:

    https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

    ACS (Consumer) URL*:

    https://XoperoONEManagementServiceURL/Auth/AssertionConsumerService

    Single Logout URL:

    https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse

    1. Click the SSO menu option on the left. Change SAML Signature Algorithm to SHA-256. Copy the Issuer URL value and save it for later— it will be needed for Xopero ONE configuration.

    1. Save all your settings. Open Users settings in the left-hand side menu, select user(s) you want to have permission to use OneLogin for Xopero ONE authentication, then in the window that pops-up, check the Allow user to sign in checkbox and hit Save.

    1. In the Applications tab, use the (+) button to add proper permissions to your custom application.


    1. Login to your XMS web panel, go to Settings (bottom-left corner in the left-hand side menu) and select External Identity Providers.

    1. Click Add new provider button and fill in the details:

    Name: your own custom name, i.e., OneLogin

    Entity ID: should be the same name you've set in Configuration (Audience (EntityID)) in OneLogin (in this example it's XOPEROSAML)

    1. Next, paste the previously copied Issuer URL in the Metadata URL field.

    1. Upload the previously downloaded OneLogin .pfx certificate file and add a password to it if required.

    2. Set up a default Language and Role for the users with OneLogin SAML authentication permissions.

    3. Click Save to finish the setup. You can now log out and test your configured SAML login integration.


    1. Go to User > Roles and create roles you would like to use (i.e., XONE viewers, XONE admins, etc.). Assign these roles to different users.

    1. Next, in Applications tab, edit the SAML application. Go to Parameters and use the (+) icon to create a new parameter. In Name field enter http://schemas.xmlsoap.org/claims/Group. Check both Flags (Include in SAML assertion and Multi-value parameter) and save your settings.

    2. In Default if no value selected section select User Roles and Semicolon Delimited input (Multi-value output) from the drop-down menu, and save the parameter.

    1. In your Xopero ONE console go to ⚙️ Settings > External Identity Providers and select the IdP you want to edit.

    2. Click the Group mapping button in the bottom left. In Claim type field enter http://schemas.xmlsoap.org/claims/Group, and in Claim value field enter the name of the role, e.g., XONE viewers. Select roles and permissions you want this group to have, then save. Repeat this step for each role/permission you want to create.

    “callback”: "https://XoperoONEManagementServiceURL/auth/SAMLLogoutResponse"

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    Configuration in Azure

    Configuration in CyberArk

    Configuration in Google

    Configuration in JumpCloud

    Requirements and limitations

    If the PKCS #12 file is password protected, add this password to the IdP configuration in Xopero ONE web panel.

    Configuration in Okta

    Configuration in OneLogin

    Using IdP authentication method

    Enabling IdP login for the root admin account will prevent logging into the system when an external provider is unavailable.

    circle-1Configuration in Azure
    circle-2Configuration in Xopero ONE
    portal.azure.com
    circle-1Configuration in CyberArk
    circle-2Configuration in Xopero ONE
    circle-1Configuration in Google
    circle-2Configuration in Xopero ONE
    circle-1Configuration in JumpCloud
    circle-2Configuration in Xopero ONE
    circle-1Requirements and limitations
    circle-2Configuration in Okta
    circle-3Configuration in Xopero ONE
    circle-1Configuration in OneLogin
    circle-2Configuration in Xopero ONE
    circle-3Group mapping
    setFilteredAttributeArray("xoperogroup", LoginUser.RoleNames, "XONE.*");
    setFilteredAttributeArray("xoperogroup", LoginUser.GroupNames, "XONE.*");

    In the above addresses, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    In the above addresses, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    In the above addresses, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    The Signature Algorithm by default is RSA-SHA256— leave it as is.

    If you also want to login to Xopero ONE from the JumpCloud panel, additionally, add your XoperoONEManagementServiceURL in Login URL field.

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    Configuration in Xopero ONE

    You can read more about adding a new password to the Password Manager in KB article.

    Learn more about roles in KB article.

    In the above address, change XoperoONEManagementServiceURL to your unique XMS URL. You can find it in your XMS login URL— it's the first part of the address (i.e., in https://12a345bc-67de-8901-2345-f6gh78901i2j.ada.xopero.com/authorization/login the part highlighted in red is the URL you need to copy).

    To properly configure logout, the private key of the entity that receives the logout request is required. You must upload a file with the .pfx extension to Xopero ONE for OneLogin integration to work properly. Unfortunately, the .pfx file cannot be downloaded directly from OneLogin— you have to use your own certificate or generate it for implementation.

    OneLogin offers a form where you can generate a self-signed certificate:

    Manually edited login details always override those set by rules or with provisioned attributes.

    Configuration in Xopero ONE

    It's important to understand that with this integration method, you cannot initiate the login from the OneLogin application page. Instead, the login must always be triggered directly from the Xopero ONE side.

    Group mapping

    You can use group mapping if you have many users whom you want to assign different permissions to.

    Each new login to Xopero ONE resets permissions to default— if you change permissions for a user it will only apply during the active session. Relogging the user will make permissions return to default.

    Group mapping configuration must be done both in OneLogin and Xopero ONE— start by configuring the OneLogin side.

    Roles and permissions
    https://developers.onelogin.com/saml/online-tools/x509-certs/obtain-self-signed-certs
    Adding a new password