SAML Configuration
When you choose SAML, each user is authenticated using the SAML single sign-on server.
- External browser authentication—Select this option to have Secure Client use a local browser for authentication. When selected, Secure Client can support other SAML-based web authentication options, such as Single Sign On, biometric authentication, or other enhanced methods that are unavailable with an embedded browser.
- Forced re-authentication—Select this option to force a re-authentication whenever a VPN connection is initiated. Forced re-authentication is related to the Session Timeout setting. For more information see Cisco Secure Client Configuration.
For more information about Secure Access and SAML for VPNs with a configured VPN profile, see Manage SAML Certificates for Identity Providers. SAML authentication for remote access VPNs supports SAML, SAML + Single CA certificate, and SAML + Multiple CA Certificates.