In Part One of this Getting Started Series, we will cover how to configure the directory of users using SAML. SAML is chosen over OIDC to future-proof your configuration so that SCIM can push user information to SonicWall Cloud Secure Edge (CSE) in a future configuration. Once this procedure is completed, you’ll be able to start registration of users, log into the CSE App, and view users and devices that have authenticated in the Command Center.
NOTE: Steps may vary based on your identity provider. You may refer to specific guides here: https://docs.banyansecurity.io/docs/manage-users-and-devices/identity-providers/ or from your identity provider’s documentation.
Section One: CSE TrustProvider
Section One will cover how to deploy the TrustProvider





TIP: You will want to hide any application tiles from the user as this connection is for the App’s authentication and should not be initiated manually by an end user as this will result in an invalid request error.
Section Two: Device Registration Provider
The second section in this part one guide is to deploy the Device Registration Provider Connection. This setup is nearly identical in procedure to Section One. However, this second connection is required and provides Reverse Device Trust Verification, authentication for Mobile Devices, tracking user emails on their device certificates, and Passwordless Authentication.





TIP: You will want to hide any application tiles from the user as this connection is for the App’s authentication and should not be initiated manually by an end user as this will result in an invalid request error. 
Validation
Part 2 of this guide series will go over registering the CSE Desktop App to validate our work here. If you hit an error in Part 2, please ensure the steps in this guide were followed.
Next Steps