SAML federation impact on multiple Carbon Black Cloud organizations using shared domains
search cancel

SAML federation impact on multiple Carbon Black Cloud organizations using shared domains

book

Article ID: 443305

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR

Issue/Introduction

Carbon Black Cloud integration with Broadcom AuthHub for SAML authentication operates on a domain-level enforcement basis. Organizations sharing a single email domain (e.g., @####.com) across multiple environments—such as NFR (Not For Resale), Development, and Production MSSP parent environments—must account for global authentication changes. This article details how enabling SAML for one environment impacts all others associated with the same domain and provides strategies to avoid production service interruptions.

Environment

  • Carbon Black Cloud (All Versions)
  • Broadcom AuthHub
  • Microsoft Entra ID (Azure)
  • Okta / Ping / Workspace One

Resolution

When enabling SAML integration via AuthHub, authentication is enforced at the email domain level rather than per Organization ID (Org ID).

  1. Domain-Wide Enforcement: Enabling SAML for a domain in any environment (e.g., NFR) automatically forces SAML authentication for all other Carbon Black Cloud Orgs sharing that domain. This includes Production MSSP parent environments.
  2. Multi-Organization Access: Users belonging to multiple Orgs under the same federated domain authenticate once via the Identity Provider (IdP). Move between environments using the Switch Organization dropdown in the console.
  3. Manual Role Assignment: Roles must be assigned manually within each Carbon Black Cloud console for every user. AuthHub does not currently support automated role mapping from IdP attributes.
  4. Test Environment Isolation: To test SAML without affecting production users, use a unique sub-domain (e.g., @test.####.com) for the NFR environment.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region. For more information on how to contact us, see Contacting Broadcom Support.

Additional Information