Skip to main content

AD_4nXe_B_5SAaiszGkiMxsiaKRxXyriHZ8q-lTt_axB0v4x-hfuWI5l0sLw6c8ZLp6mgrSsj6_TbVH_C16OcU3oCpgkn30ze5DJBDRB221UXNsr2AG-nDk7isngNyRt5dYuwC9DQzzMMhb9cHrmrmveBCBxwLab?key=Q_nbmmxTFOPP0SxtuZutKw

Netskope Global Technical Success (GTS)

Streamlining Identity Management: How to Configure Multiple IDPs
 

Netskope Cloud Version - 122

 

Objective
This document provides step-by-step instructions to help our customers configure multiple IDP setup for admins & Users

 

Details
When configuring Multiple IDPs for the Administrators or Users to access/forward traffic to Netskope
Below are the prerequisites:

  • Flag should be enabled - “Multiple IDPs Support for Management Console SSO”
  • Admin access to Netskope tenant

 

Step-by-Step configuration is below -

 

Configuration

For Administrators

  1. Add all the admin SSO domains Netskope Database]

Path: Netskope UI >>> Settings >>> Administration >>> Internal Domains

AD_4nXekH5rNQoAxIJfu4zKh9_vkRb_h3LMud-Ror1v6ykrc2XW7_55r0Hig5W8kGfuTnaicpP6T2rb_Dho4EWJ9M93h-t6adBVqJmIAd9GlRTnkI-pmOFKRYxKJPZ5fRkXUTKCiRQZWc8janwwk0RvwlIeDZH8?key=Q_nbmmxTFOPP0SxtuZutKw 

 

  1. Configure all the IDPs with their preferred domains

Path: Netskope UI >>> Settings >>> Administration >>> SSO

AD_4nXeiDx3mHyRHyG8Na59Vd8rDNQLwuNz6Xeh7VhtGZyVgUgEsMnSNi6zN6WY12ZJngqXqfHkPOWLPnYHfZ6incv-2PNLLDrVuwKgWiWzzU6giGWzdTyfO-61p4xAjdz7EaM5HaKeLgzrp-apRYJ_gk78bit2O?key=Q_nbmmxTFOPP0SxtuZutKw

 

  1. Login into the Netskope tenant, prompt will ask for admin email in order to search for the domain and redirect the admin to their appropriate IDP to authenticate.

Path: Netskope Tenant URL: https://<tenant>.goskope.com/ns#/login/sso?windowName=

AD_4nXeu4mskbtxoGp5UYXUGCrjBCeiB4Gih7rEtY0Tlu0A-q-UwICmCesYaq26DCU4z-NSHSrvWIHeHoNN-QpYD8DspcHDwRM84FzRaYMfr76hKmAhOltpBxmD99fqWgOQUUeozSYhSmUT_W9EQbT71X-9Pj6Dg?key=Q_nbmmxTFOPP0SxtuZutKw

 

AD_4nXdHunIMj_qPozRHxLtCd4m14upODOtM217JkFzCKLBxT6H2cFcCeVQjw3m9_OdCb_0TL2E7UHAJ3v3Tqc932-KZyXSDkY4-ngztZQIuUDaf3sIApmZ0zQuI67miemzqNgO1o58bRRHCk20FeVI6RN6whf_y?key=Q_nbmmxTFOPP0SxtuZutKw
 

 

For Users

  1. Configure All the IDPs with their preferred domains

Path: Netskope UI >>> Settings >>> Security Cloud Platform >>> Forward Proxy >>> SAML

AD_4nXfWUdrJLQJksT68_g9AwoOEOK2yqVUBftmjWgoRucNx59rO0_E4Bbp6FUvGoAR3fL_Ihv16oYUhEtTSfh1lKaBrRcv50k31YExxRKyj85ZA47h20SDs9_7g64iLl3RZjMVgX7PfHzwKKrQIL42Z1oSvPqEP?key=Q_nbmmxTFOPP0SxtuZutKw


Note:

When we edit the configuration of the IDP under the optional page we have to add the preferred domains for the IDP.

 

Example:

  • For Azure the user Authentication domain is :- M365x51510246.onmicrosoft.com
  • For Okta the User Authentication domain is :- spark.com

AD_4nXfiTLlJ2IKR_IYk3xNiWvSbkAGnT80-x_JVNZuY5IU2m-kmHXjSbE5mclXDGHP10NDLxRTRpftjoFwz3KwAeovOEqFtoC_rnoruwpVSUU_pc4xC7yJVFqqdupUttBHAenmJFKhHL13-2LJMxWl9xMcaN8Jw?key=Q_nbmmxTFOPP0SxtuZutKw


AD_4nXccKF4Mas4SnLA1RKJYBOlCLM2KNUGB34MfDUHl0fNY5NnFwEcU5e9gNghRh535nChEnzjZ6DkEhHjl8KrkV3R82ydyA_2iyL_HBp8CThg2Cfabc3qyPGE_8lrOpUia9mniIFadoHmTZMsfRz1t_i0YI_fH?key=Q_nbmmxTFOPP0SxtuZutKw
 

  1. Login to the Netskope Client

    We will observe a pop-up to identify the Organisation if not installed using token
    AD_4nXdNwvSeavhzReKStsuyH7zqNZravMwyyV0qamCrsc2GROBJzl7qzkjonAHXbh4uyv2WYNKe2-n7RokbclgVMuSaZTgO1qpBFe2ELpVWxuSuSszYfMQOZHTIluJ65MWNr1VfG08_zn6FvyOHm8wI_QRNXvs?key=Q_nbmmxTFOPP0SxtuZutKw

    If the token is already embedded in the installation script of Netskope Client - we will directly see the below screen.
     

# Pop-up for user email in order to search for a domain to redirect the user to correct IDP for authentication.

AD_4nXcRgw7-RnS5rn5q0rsiNN2QR4vxmUgLHMQsACLSakbrT45CLWNmcDo61TmB6VR40_hGPQ9TlOo36ojK9SbxOr0aDju9Rq9lBv66tX6GBlOLmzasOWodN38qMTxIdw8wSYezB126w4EP8ETCX-qTBY8Zfa1i?key=Q_nbmmxTFOPP0SxtuZutKw

 

Multiple IDPs provide both convenience and security, making it easier to manage access across different user groups while maintaining robust security practices.

 

Benefits of Multiple IDP Environment

  • Flexibility: Supports various user groups with different authentication needs. (Employees, External users, Contractors, Customers, Partners)
  • Security: Enforces different levels of security based on user roles and regions.
  • Scalability: Adapts to organizational changes, such as mergers, acquisitions or multi-regional operations.
  • User Experience: Simplifies login processes by allowing users to authenticate with their preferred IDP.
  • Compliance: Ensures adherence to regional and industry-specific regulations.


Example: Microsoft, Google, Amazon, Cisco, and Salesforce, use a multi-IDP approach to provide secure, flexible access to management consoles and services.
 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, If any such platform changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.