Software Secure Access
Activity Manage

Step 3b – Add Secure Access Service Provider Metadata to Entra ID

Configure Secure Access as a generic SAML 2.0 service provider application for Entra ID. Add the Secure Access service provider metadata to Entra ID, then download the IdP metadata file from Azure to finish configuring Secure Access in the next step.

Contact Microsoft for assistance. For more information on configuring your IdP, exporting your IdP metadata, obtaining your IdP details, or downloading your IdP's signing certificate, refer to Microsoft documentation.

To configure the generic SAML Entra ID application, extract the EntityID and AssertionConsumerService values from the Secure Access metadata file and add these to the applicable fields in Entra ID:

  1. Sign in to Azure and navigate to Azure services > Enterprise Applications.

  2. Select New Application.

  3. Select Create your own Application.

  4. Give the new application a meaningful name, select Integrate any other application you don't find in the gallery (Non-gallery), and then click Create.

  5. Navigate to Getting Started, and then click Set up single sign on.

  6. Click SAML to select the sign-on method.

  7. For Basic SAML Configuration, click Edit.

    1. For Identifier (Entity ID) (Microsoft Entra ID), click Add identifier and enter saml.fg.id.sse.cisco.com in the text area.
    2. For Reply URL (Assertion Consumer Service URL), click Add reply URL and enter https://fg.id.sse.cisco.com/gw/auth/acs/response .
  8. Navigate to SAML Certificates, and then Verification certificates (optional).

  9. Click Edit.

  10. Chose Require verification certificatess and then click Upload certificate.

  11. Upload the root certificate that you downloaded from the Cisco_SSE_SP_Metadata XML file, and then click OK.

  12. Navigate to SAML Certificates > Token signing certificate.

  13. For Federation Metadata XML, click Download.

    Save the Federation Metadata XML file to your system and use the file to upload the configured Entra ID SAML attributes to Secure Access.