After you configure federated SAML single sign-on (SSO) with Broadcom Login for one or more Broadcom services, administrators suddenly lose administrative access to their other Broadcom services.
Broadcom Login and SAML or a SAML-based IdP are configured on two or more of the following services:
Note: Broadcom is aware of this issue affecting the services in this list. If other affected services are identified, this KB article will be updated.
When you configure federated SSO through Broadcom Login, all services that support SSO through Broadcom Login will use your configured IdP. This change can cause the following unexpected behaviors:
For example, the following scenarios result in a mismatch between the administrators in the IdP and in Broadcom services:
Administrators must have valid accounts in the IdP and in the appropriate services. Compare the list of administrators in the IdP with the list of administrators in the services. Then, ensure that all administrators have valid accounts in the IdP and in the services.
Complete the following steps in the specified order:
Important Notes
Services that support group-based access control: Whenever you synchronize user lists between the IdP and services, contact Broadcom Support to ensure that the user record is updated in Login and in all services. Otherwise, the sync can result in users with multiple identities in Login and mismatched names in services, which will cause access issues.
Service | Instructions |
AppNeta | |
Broadcom Support Portal |
Refer to your Broadcom product representative (for example, your Symantec, Clarity, or Rally point-of-contact) to enable SSO Federation with Broadcom’s customer identity tenant. After federation is set up, the Broadcom product team will reach out to Broadcom’s Identity & Access Management (IAM) team to complete the configuration for federated access to the Broadcom Support Portal. |
Cloud SWG (WSS) |
Add a Cloud SWG Administrator |
CWA | Managing user accounts in Cloud Workload Assurance |
CWP | |
CloudSOC CASB |
Contact Broadcom Support to use the Broadcom Login feature. See the Symantec CASB CloudSOC Release Notes for more information. |
CMP | Add or Delete CMP Administrators |
Email Security.cloud |
|
SES |
Configure group-based administrative roles. Caution: If other Broadcom services were configured for Login IdP previously, be careful not to inadvertently remove user lists when you configure the role mapping in ICDm. Configuring a SAML 2.0-based identity provider for Symantec Endpoint Security Configuring Microsoft Azure using SAML 2.0 as your identity provider in Symantec Endpoint Security |