Before getting started, please take a look at these  links below. The customer should have  these set up in their Azure:

To configure SAML on Chronicle SOAR:

  • Navigate to Settings > Advanced > External Authentication.
  • Select the Custom SAML Provider.
  • Fill out the following.
    • Provider Name: Azure
    • IDP Metadata: Click Download next to the Federation Metadata XML in the SAML screen
    • Identifier: Copy what is written in the Azure AD Identifier field in the SAML screen
    • Audience URI (SP Entity ID): For example: https://platform_Address/Saml2/. You will add this later on to the SAML screen
    • Provider Public Certificate: download the Certificate (Base64) from Azure in the SAML screen.

To Configure SAML on Azure:

Navigate to Azure > Basic SAML Configuration and configure the following:

Identifier (Entity ID): https://platform_Address/Saml2/ (take this from the Chronicle SOAR platform)

Reply URL (Assertion Consumer Service URL): https://platform_Address/Saml2/ACS