Configuring the One Identity Cloud Access Manager (CAM) as an SMA appliance is done by setting up a One Identity CAM Authentication Server on an SMA appliance.
To configure the One Identity CAM as an SMA Authentication Server
In the AMC, navigate to System Configuration > Authentication Servers.
Under Authentication servers, click the + (New) icon. The Add Authentication Server page displays.
Select SAML 2.0 Identity Provider.
Click Continue.... The Edit Authentication Server page displays.
Some of the values for the fields in the Configure Authentication Server page can be obtained from the Application Created page of the One Identity Cloud Access Manager.
The steps that follow explain how to configure the fields in the Configure Authentication Server page.
In the Name field, enter CAM.
https://appliance.company.com.urn:cam.test.com.test.com/CloudAccessManager/RPSTS.In the Authentication service URL field, enter the IDP Login URL from the Application Created page. For example,
https://sp16.test.com/CloudAccessManager/RPSTS/Saml2/Default.aspx.
https://cam.test.com.com/CloudAccessManager/RPSTS/Saml2/Default.aspx.From the Trust the following certificate drop-down menu, select the certificate you want. This should be the certificate from the Certificate (Download Certificate) of the Application Created page.
You must first download and install the certificate you want before it can appear in this drop-down menu. See Downloading a Certificate for instructions on how to do this.
SMA supports group membership details over SAML authentication and users without on-premise Active Directory can now have group level management. In the SAML claim containing user groups field, specify the name of the claim that contains the group information. For example: http://schemas.microsoft.com/ws/2008/06/identity/claims/groups.
The SAML claim containing user groups field is configured with user group attribute name, for more information, refer to the Group Management with SAML IdP authentication server section.
Enable Force users to re-authenticate to ask the Identity Provider to check the user’s credentials every time they log into their account.
Click Save.