Client performs the following steps to ensure that all CASB (CloudSOC) SysAdmins and Admins can login with a minimal amount of downtime.
Verify CloudSOC SuperAdmin is enabled for CloudSOC\DLP\Cloud SWG in the Enterprise Security Console | Common Settings. Anyone with Account Settings Manager right can add SuperAdmin as needed.
1. Create a SSO object for "Broadcom Login" in your Corporate Entra Enterprise Apps
Select "Setup Single Sign" (on left pane)
Note: The Identifier Entity ID and Reply URL you entered above are temporary entries. These will be replaced later with two valid URLs you'll receive from Broadcom Support
2. Add your CASB SysAdmin and Admin users to your "Broadcom Login App" in Entra
3. Continue uploads the Federation Metadata XML file (downloaded on step 1) to Identity Provider Configuration Wizard
Your Entra SSO IdP Broadcom Login App attribute mappings MUST match the standard attributes within Broadcom’s IDP (as shown below):The default mapping for azure may look like the follow. Customer must verify.
|
|
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress |
|
FirstName |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname |
|
LastName |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname |
|
Groups |
http://schemas.microsoft.com/ws/2008/06/identity/claims/groups |
|
UserId |
http://schemas.microsoft.com/identity/claims/objectidentifier |
4. Update the Entra SSO Basic SAML Configuration using information provided in Identity Provider Configuration Wizard
Copy AUDIENCE URI to Entity ID
Copy ACS URL to Reply URL
CASB (CloudSOC) SysAdmin or Admin using the new Entra Broadcom Login App should get redirected to Broadcom Login, Microsoft platform, and then redirected back to CASB.