Skip to main content
Solved

SAML Configuration working top to bottom

  • August 9, 2024
  • 2 replies
  • 102 views

Jais100rbh
Netskope Partner
Forum|alt.badge.img+5

HEllo,

 

I need help understanding the SAML configuration. Does it work with a top-to-bottom approach? I've set up a forward proxy SAML for two IDP domains (for example, abc.com and xyz.com) for Netskope client enrollment. However, when I try to enroll the Netskope client with the xyz domain, the authentication page redirects to abc.com. Upon checking bypass settings, I found that it's a global setting for all SAML configurations. I need a quick response to achieve and segregate authentication for both domains.

Best answer by sshiflett

Hello @Jais100rbh

Yes SAML forward proxy is a top down, first match configuration.  You can specify an authentication domain per IDP under the Options tab:
 

Your users will be prompted for their email/username and this will be used to determine which IDP to use for authentication. 

 

This topic has been closed for replies.

2 replies

Forum|alt.badge.img+16
  • Netskope Employee
  • Answer
  • August 12, 2024

Hello @Jais100rbh

Yes SAML forward proxy is a top down, first match configuration.  You can specify an authentication domain per IDP under the Options tab:
 

Your users will be prompted for their email/username and this will be used to determine which IDP to use for authentication. 

 


Jais100rbh
Netskope Partner
Forum|alt.badge.img+5
  • Author
  • Netskope Partner
  • August 20, 2024

Hello @sshiflett,

 

With your expertise and suggestions, I am able to segregate both domains. 

Thanks for your prompt response :)