CASB (CloudSOC) customers can now choose to connect their Corporate Azure SSO IdP with Broadcom OIDC SSO Federation for CASB SysAdmin & Admin logins
Broadcom OIDC SSO Federation logins will eventually become mandatory for CASB and all Symantec Enterprise Division (SED) Cloud products
Client performs the following steps to ensure that all CASB (CloudSOC) SysAdmins and Admins can login with a minimal amount of downtime.
1. Create a SSO object for "Broadcom Login" in your Corporate Azure Enterprise Apps
Select "Setup Single Sign" (on left pane)
Note: The Identifier Entity ID and Reply URL you entered above are temporary entries. These will be replaced later with two valid URLs you'll receive from Broadcom Support
2. Add your CASB SysAdmin and Admin users to your "Broadcom Login App" in Azure
Notes: It is Strongly recommended to have a backup CASB (CloudSOC) SysAdmin with an email address in another (secondary) domain in case the IDP server is down. Should SSO be unavailable, the SysAdmin with a non federated secondary domain email address should still be able to perform a local login to CASB (CloudSOC)
Your Azure SSO IdP Broadcom Login App attribute mappings MUST match the standard attributes within Broadcom’s IDP (as shown below):
3. Customer uploads the Federation Metadata XML file (downloaded on step 1) to a new CASB Support Case
Broadcom Support will process the XML file, Azure IdP code and provide following for Customer to copy paste back into Azure SSO Broadcom Login App
4. After Broadcom Support responds in your CASB Support Case with custom values for your Broadcom Login App ("REPLY URL/ACS" and "AUDIENCE URL/EID")
Edit your Broadcom Login App in Azure AD Enterprise Apps and insert the Identifier Entity ID and REPLY URL that you receive from Broadcom Support in your Support case.
(CAUTION: Screenshots below are only examples of what you will receive from Broadcom CASB Support - DO NOT USE the values below in your Azure SSO IdP environment!)
5. Test the SSO login.
Troubleshooting
CASB (CloudSOC) SysAdmin or Admin using the new Azure Broadcom Login App should get redirected to the Azure IDP SSO server to login, then be connected to CASB