Use this application method if you do not have a user directory, such as AD, on-premise. In this method, details about user groups or roles are sent from OneLogin to the SMA1000.
If you have a user directory like AD on-premise, you can integrate it directly with SMA1000 for all group-level authorisations while still using OneLogin for user authentication. In this case, see Configuring SMA1000 at OneLogin using the SonicWall application.
To add the SAML Custom Connector (Advanced) application with SMA1000 details do the following
On the OneLogin admin portal, go to Applications > Add App.
Search and add the "SAML Custom Connector (Advanced)" application.
Enter an application name. Example: Sonicwall SMA1000.
Click Save.
Click the Configuration tab.
Enter the Audience (EntityID) value as the workplace URL. Example: https://workplace.company.com
Enter ACS (Consumer) URL value as "https://workplace.company.com/saml2ssoconsumer".
Keep all other values as default.
Click Save.
To send user groups or roles information to SMA1000 during user logins do the following:
Click the Parameters tab on the left pane.
Click + icon to add new field.
Enter a name for the field.
Example, enter Groups (when sending AD groups to SMA1000).
Example, enter Roles (when sending User roles to SMA1000).
Enable Include in SAML assertion checkbox.
Enable Multi-value parameter checbox.
Click Save.
For Default, if no value is selected in the option, expand the first dropdown box and choose either MemberOf or User roles option based on whether you want to send user groups or roles information.
For the second dropdown box, select the Semicolon Delimited input (Multi-value output) option.
Click Save.
Review values in other tabs. Default values are usually sufficient.
Click Save to save your configuration.
After you have configured go to Configuring SMA1000 Appliance.