ADFS on-prem Setup for Carbon Black Cloud / Authhub
search cancel

ADFS on-prem Setup for Carbon Black Cloud / Authhub

book

Article ID: 420764

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard

Issue/Introduction

  • This document provides the steps needed to setup on-premise ADFS SAML 2.0 with Carbon Black Cloud.
  • For the time being this process requires the help of Support. In the future this will be available via self service.
  • This article previously provided steps for customers to migrate to Authhub. Now that all customers have been migrated, this article is for initial SAML setup.

Environment

  • Carbon Black Cloud Console: Current Version
  • Microsoft Windows ADFS on-premise 

Resolution

  1. Open the ADFS Management Console
  2. Open the Relying Party Trust folder, setup a new entry for Carbon Black Cloud, and select properties.
  3. Under the Monitoring tab, if the Monitor Relying Party is checked, uncheck the box to allow the configuration to be modified.


  4.  Switch to the Identifiers tab - 

    Update the Display Name field if required (display name for relying party trust), and remove the existing Relying Party Identifier - 



  5. Once removed add the following Identifier - https://access.broadcom.com/default in the Relying Party identifier field and select Add -



  6. Select the Add SAML option, and add the following Endpoints > https://access.broadcom.com/default/saml/v1/sp/acs




  7. Confirm the changes and hit apply.
  8. Right click the Relying Party Trust and select Edit Claim Issuance Policy
  9. Ensure that the email claim is setup as the following by selecting the rule, and selecting edit rule



  10. If you are making use of an outgoing transformation rule, set it up as such:


  11. Open the Federation Metadata file for the ADFS server, typically available from https://<server host name>/FederationMetadata/2007-06/FederationMetadata.xml and share this .xml file with the Carbon Black Support team via the Wolken Support case.
  12. Carbon Black Support will generate an Authhub.xml file with the unique Audience URI that will need to be updated in the ADFS Relying Party Trust via import.
  13. Validate the connection by attempting to signin into the CB Cloud console via an incognito browser window.