Enabling SAML Federation For Carbon Black Cloud
search cancel

Enabling SAML Federation For Carbon Black Cloud

book

Article ID: 291414

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter) Carbon Black Cloud Workload

Issue/Introduction

To enable SAML for login with the Carbon Black Cloud Console

Environment

  • Carbon Black Cloud Console: All Versions

Resolution

  1. Open a Technical Support case
  2. Provide the following information:
    • IDP Code - An email domain for the new IdP.
    • Metadata - Upload an XML file from your IdP that contains IdP metadata.
    • Attribute mappings - Default attribute names must be reviewed and updated to match your IdP attribute names. The following attributes are required:
      • Email
      • FirstName
      • LastName

Additional Information

  • SAML authentication is configured per email domain. If you add users to the Carbon Black Cloud console (Settings > Users) using an email domain that is not configured for SAML, they will bypass SAML authentication and serve as emergency "break-glass" accounts.
  • IDP-initiated logins are not supported; that is, clicking on a tile from your provider (Okta, Azure, and so on) will not automatically log you in. Such a tile must be a bookmark to the Carbon Black Cloud portal that is associated with your Carbon Black Cloud backend.