Platform GCP
Activity Upgrade

Relationship Between the Identity Provider Accounts and Firewall Manager User Records

To log in to Firewall Manager, a customer needs an account with a SAML 2.0-compliant identity provider (IdP), a multi-factor authentication provider, and a user record in Firewall Manager. The IdP account contains the user's credentials and the IdP authenticates the user based on those credentials. Multi-factor authentication provides an added layer of identity security. The Firewall Manager user record primarily contains the username, the Firewall Manager tenant with which they are associated, and the user's role. When a user logs in, Firewall Manager tries to map the IdP's user ID to an existing user record on a tenant in Firewall Manager. When Firewall Manager finds a match, the user is logged in to that tenant.

Unless your enterprise has its own single sign-on identity provider, your identity provider is Cisco Security Cloud Sign On. Cisco Security Cloud Sign On uses Duo for mutli-factor authentication. Customers can integrate their own IdP with Firewall Manager if they choose.