Integrate Microsoft Entra SSO with Skyhigh SSE Dashboard
This topic describes how to integrate Microsoft Entra SAML-based SSO with the Skyhigh SSE Dashboard.
Prerequisites
Before you begin, make sure you have:
- Admin access to Microsoft Entra.
- Admin access to the Skyhigh SSE Dashboard.
- Users created in the Skyhigh SSE Dashboard with first and last names that match the Entra user details (automatic user provisioning is not supported).
- (Optional) User groups in Entra to simplify SSO assignment.
Steps to Integrate
Integrate SAML-based SSO in Microsoft Entra and the Skyhigh SSE Dashboard with the following steps:
- Microsoft Entra Configuration
- Configure Skyhigh SSE Dashboard Settings
- Update Basic SAML Configuration in Microsoft Entra
- Test Single Sign-On
- Troubleshoot SSO Login Errors
Microsoft Entra Configuration
- Sign in to the Azure portal.
- Go to Enterprise applications > All applications.

- Click New application.

- Click Create your own application.

- In the Create your own application side panel, enter a name for the application (for example, Skyhigh SSE Dashboard).

- Open the newly created application, and go to Manage > Single sign-on > SAML.

- Edit the Basic SAML Configuration settings and enter the following temporary values:
- Identifier(Entity ID).
https://auth.ui.trellix.com - Reply URL(Assertion Consumer Service URL).
https://auth.ui.trellix.com - Relay State(Optional).
https://auth.ui.trellix.com
- Identifier(Entity ID).
NOTE: Update these values after configuring in the Skyhigh SSE Dashboard Settings.

- Configure Attributes & Claims as required.

- Download the certificate (Base64 format).

- Click
to copy the Login URL and Microsoft Entra Identifier.

Configure Skyhigh SSE Dashboard Settings
- Log in to the Skyhigh SSE Dashboard with Admin access.
- Go to User Menu > Identity Provider.

- Edit the configuration:
- Enable Identity Provider SSO.
- Enter the Microsoft Entra Identifier in the Issuer field.
- Upload the Base64 certificate.
- Enter the Login URL.


- Enable SAML Exception for the Break Glass Account (recommended).
- If applicable, apply an exclusion for the Cloud Connector user (non-SAML).

- Click
to copy the generated Audience and Assertion Consumer Service (ACS) URL, then save the changes.

Update Basic SAML Configuration in Microsoft Entra
- In Microsoft Entra, go to Basic SAML Configuration.
- Replace the temporary Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) values with the final values from the Skyhigh SSE Dashboard.

- Assign users or groups:
- Go to Groups > Add Users/Groups.
- Select and assign the required users or groups.
Test Single Sign-On
- Log in to https://myapps.microsoft.com using a user account assigned to the Skyhigh SSE Dashboard.
- Click Skyhigh SSE Dashboard to launch the application.
- Verify that the login is successful and does not prompt for a username or password.
Troubleshoot SSO Login Errors
SSO login may fail if user details in the Skyhigh SSE Dashboard do not match those in Microsoft Entra.
To troubleshoot:
- Collect SAML tracer logs and verify the claim attributes.
- Ensure that the First Name and Last Name in the Skyhigh SSE Dashboard exactly match the user details in Microsoft Entra.
