Single Sign On (SSO) with SimpleMDM
- A public certificate and private key pair are required to successfully connect applications with JumpCloud. After you activate an application, we automatically generate a public certificate and private key pair for you. You can use this pair or upload your own.
- To successfully complete the integration between JumpCloud and SimpleMDM, you need to use an administrator account in SimpleMDM.
Configure the JumpCloud SSO Application
- Access the JumpCloud Administrator Console at https://console.jumpcloud.com.
- Select Applications in the main navigation panel.
- Select the + in the upper left, scroll or search for the application in the 'Configure New Application' side panel, then select 'configure'.
- Optionally, enter SimpleMDM for the Display Label. This label will appear under the Service Provider logo in the JumpCloud User Portal.
- You can upload a service provider application's XML metadata file to populate SAML connector attributes for that application. The attributes populated by the metadata file may vary by the application. To apply a metadata file for the application you're connecting, click Upload Metadata. Navigate to the file you want to upload, then click Open. You'll see a confirmation of a successful upload. Be aware that if you upload more than one metadata file, you'll overwrite the attribute values applied in the previously uploaded file.
- In the IDP Entity ID field, enter
- In the SP Entity ID field, enter the value from the Audience field. You can get this value from SimpleMDM.
- In the ACS URL field, enter the value from the SAML Consumer URL field. You can get this value from SimpleMDM.
- In the Signature Algorithm field, select 'RSA-SHA256'. If your Service Provider doesn't support 'RSA-SHA256', then select 'RSA-SHA1'.
- In the field terminating the IdP URL, either leave the default value or enter a plaintext string unique to this connector.
- Select Activate.
Configure the Service Provider
- Log in to the SimpleMDM Administrator Console.
- Go to Settings > Users.
- Select the Settings tab.
- Under the Single Sign On with SAML section, select Yes to enable SAML.
- In the Short Name field, enter your one-word company name. This name can only be one word can can't contain any spaces.
- Click Save. The fields under SimpleMDM Information will automatically populate.
- Under Identity Provider Information, in the Endpoint URL field, enter
- In the X.509 fingerprint or certificate field, drag and drop your cert.pem file generated according to the previously mentioned prerequisites.
- Click Save.
Validate SSO authentication workflows
- Access the JumpCloud User Console at https://console.jumpcloud.com.
- Select the Service Provider icon.
- This should automatically launch and login to the application.
- Navigate to your Service Provider application URL.
- You will be redirected to log in to the JumpCloud User Portal.
- The browser will be redirected back to the application and be automatically logged in.