Scenario:
Proofpoint Essentials supports integration with Identity Providers for authentication adhering to Security Assertion Markup Language (SAML) standards. Multiple identity providers for an organization are fully supported.
Proofpoint Essentials supports single sign-on (SSO) via Security Assertion Markup Language. When working with an external IdP, it can be set up as your identity provider (IdP) for SSO to Proofpoint Admin Console.
Okta SAML/SSO Configuration:
- Navigate to Administration > Account Management > Identity Providers.
At the top right-hand corner, click Add Identity Provider.
In the New Identity Provider dialog panel, add a meaningful name and description to the Identity Provider. The given name will display on the Identity Provider button on the main login screen.
In the Icon section, select the appropriate icon according to your desired integration (Okta).
- Click Next
Configuring SAML/SSO In Okta Portal
Log into Okta as administrator.
Select Application > Add a New SAML App - > Create SAML Integration.
Give your app a name and select next.
Copy and paste the values from Proofpoint Essentials Identity Provider setup into the following fields.
Okta
Proofpoint Essentials
Single sign on URL
Login URL Audience URI (SP Entity ID)
Entity ID
Single Logout URL Logout URL Check/Tick Use this for Recipient URL and Destination URL
Change Name ID format to EmailAddress
Change Application username to Email
Under Signature Certificate, add Certificate from Essentials IDP create (Upload file with cert) (For this step, copy the X.509 Certificate value from ProofPoint Portal into a basic text editor and save into ProofPoint.cer (Notepad recommended for Windows users, do not use Word). You might get a 1 day expiry notice at this step, you can ignore the notification and continue.
Click Finish.
Click View SAML setup Instructions
16. Copy and paste the values into Proofpoint Essentials Identity Provider setup from the Okta SAML setup instructions.
Microsoft Azure | Proofpoint Essentials |
---|---|
Identity Provider Issuer | Identity Provider Single Sign-On URL |
Identity Provider Single Sign-On URL | Identity Provider Login URL |
Identity Provider Single logout URL | Identity Provider Logout URL |
X.509 Certificate | Identity Provider X.509 Certificate |
17. Click Enable Single Sign-On. When enabled, the Identity Provider Sign in with button will display on main login screen.
18. Click Save and Close.
19. Finally, ensure users or groups are assigned to the application to enable SSO usage.