Skip to main content

Configuring Bitdefender services single sign-on with Microsoft Entra ID

GravityZone supports single sign-on (SSO) for Bitdefender services outside GravityZone Control Center, such as MDR portal, through the GravityZone IdP Proxy. The IdP Proxy uses SAML 2.0 as authentication standard.

This topic describes how to configure single sign-on for Bitdefender services with Microsoft Entra ID (formerly Azure Active Directory). For generic information on configuring other identity providers, refer to Configuring single sign-on for Bitdefender services using a 3rd party identity provider.

Configuring SSO with Microsoft Entra ID involves many small steps, mostly in the Microsoft Entra admin center, so follow the procedure described below carefully.

Note

Microsoft Entra ID was formerly known as Azure Active Directory (Azure AD). The functionality is the same; only the product name and admin portal have changed.

Prerequisites and requirements

  • You have a Microsoft Entra ID account with at least the Cloud Application Administrator or Application Administrator role assigned.

  • You have a GravityZone Cloud administrator account to manage users, your company and other companies.

  • GravityZone users have Microsoft Entra ID accounts with the same email addresses.

  • GravityZone Control Center SSO with Microsoft Entra ID is already configured and working. Refer to Configuring GravityZone Control Center single sign-on with Entra ID.

  • Users are configured with the Login using your Identity Provider authentication method in GravityZone account settings.

    Note

    This option is only available after GravityZone Control Center SSO has been configured at the company level.

Configure Microsoft Entra ID

To enable single sign-on for Bitdefender services with Microsoft Entra ID, you can configure a separate enterprise application for the GravityZone IdP Proxy. This is in addition to the existing application used for GravityZone Control Center SSO.

This is how you create and configure the application:

Extract the GravityZone IdP Proxy SAML metadata

  1. Log in to Bitdefender GravityZone as an administrator.

  2. Click your user name in the upper-right side of the screen and select My Company.

  3. Go to the Authentication tab.

    gz_authentication_sso_services_cp_1573151_en.png
  4. Under the Bitdefender services single sign-on section, click the button next to the GravityZone IdP Proxy SAML metadata URL field to copy the metadata URL.

    gz_sso_idp_proxy_metadata_url_field_1573149_en.png
  5. Open the metadata URL in a separate tab of your browser and save the page as a metadata.xml file.

    gz_sso_idp_proxy_metadata_file_1573149_en.png

Keep the metadata.xml file open for reference during the Okta configuration. You will need the Entity ID and Assertion Consumer Service URL values from the metadata.

gz_sso_idp_proxy_metadata_file_opened_1573149_en.png

Set up your application

  1. Log in to the Microsoft Entra admin center: https://entra.microsoft.com

  2. In the left-side navigation, under Entra ID, go to Enterprise apps.

    sso_entra_01_menu_ent_apps_cp_1577378_en.png
  3. At the top of the page, click + New application.

  4. Click Create your own application.

    sso_entra_02_create_app_cp_1577378_en.png
  5. In the Create your own application panel:

    1. Enter a relevant name (for example, GravityZone IdP Proxy),

    2. Select Integrate any other application you don't find in the gallery (Non-gallery).

      sso_entra_03_app__name_cp_1577378_en.png
    3. Click Create.

Assign users and groups

  1. In the application overview page, go to Users and groups in the left-side navigation.

  2. Click + Add user/group.

    sso_entra_04_app_users_groups_cp_1577378_en.png
  3. In the Add Assignment page, click None Selected under Users and groups.

    sso_entra_05_app_none_selected_cp_1577378_en.png
  4. In the right-side panel, select the users or groups that should have access to Bitdefender services through GravityZone IdP Proxy and click Select.

    sso_entra_06_app_user_selected_cp_1577378_en.png
  5. Back in the Add Assignment page, click Assign to confirm.

    sso_entra_07_app_assign_cp_1577378_en.png

Configure SAML single sign-on

  1. In the application's left-side navigation, go to Single sign-on.

  2. Select SAML as the single sign-on method.

    sso_entra_08_app_saml_cp_1577378_en.png
  3. In the Set up Single Sign-On with SAML page, complete the following sections:

Basic SAML Configuration

  1. Click the pencil icon to edit.

    sso_entra_09_app_basic_saml_cp_1577378_en.png
  2. Configure the following fields using values from the GravityZone IdP Proxy metadata:

    1. Identifier (Entity ID). Enter the Entity ID from GravityZone IdP Proxy metadata XML.

    2. Reply URL (Assertion Consumer Service URL). Enter the Assertion Consumer Service URL from the IdP Proxy metadata XML.

    3. Sign on URL. Enter the same Assertion Consumer Service URL.

    4. Relay State. Leave blank.

    5. Logout URL. Leave blank.

    sso_entra_10_app_basic_saml_fields_cp_1577378_en.png
  3. Click Save.

Return to the setup page.

Attributes & Claims

  1. Click the pencil icon to edit.

    sso_entra_11_app_attributes_claims_cp_1577378_en.png
  2. Verify the Unique User Identifier (Name ID) claim.

    sso_entra_12_app_name_id_cp_1577378_en.png

    Click the entry to edit as follows:

    • Source attribute should be set to user.mail.

    • Name identifier format should be set to Email address.

    sso_entra_13_app_name_id_fields_cp_1577378_en.png

    If the default configuration uses user.userprincipalname, this is also acceptable as long as the UPN matches the email address configured in GravityZone.

  3. Click Save if you made changes.

Return to the setup page.

SAML Certificates

  1. In the SAML Certificates section, verify that a signing certificate is active.

  2. Copy the App Federation Metadata Url. This is the identity provider metadata URL you will need for GravityZone. Click the copy icon next to the URL.

    Note

    Keep this URL at hand. You will paste it in GravityZone Control Center in the next step.

    sso_entra_14_app_certificate_cp_1577378_en.png

Enable SSO for Bitdefender services in GravityZone

After configuring your application in Microsoft Entra ID, go to GravityZone Control Center to enable SSO for Bitdefender services.

Enable SSO for your company

This is how you enable SSO for Bitdefender services for your company:

  1. In the upper-right corner of Control Center, click the user icon and then select My Company.

  2. In the Authentication tab, under Bitdefender services single sign-on, enter the identity provider metadata URL in the Identity provider metadata URL (IdP Proxy) field. The other field, reserved for the GravityZone IdP Proxy SAML metadata URL, is non-editable.

    Paste the App Federation Metadata Url you copied from the Microsoft Entra admin center.

    If you did not save it, go to Microsoft Entra admin center > Identity > Applications > Enterprise applications > [your application] > Single sign-on. The App Federation Metadata Url is available in the SAML Certificates section.

    gz_sso_idp_metadata_url_field_1573149_en.png
  3. Click Save.

Verify the authentication method for users

Users must have their authentication method set to Login using your Identity Provider in GravityZone account settings. If GravityZone Control Center SSO is already configured and users are already logging in with your Identity Provider, no additional changes are needed.

If any users still use GravityZone credentials:

  1. Log in to GravityZone Control Center.

  2. Go to the Accounts page from the left side menu.

  3. In the table, click the user's name.

  4. Under Login Security, go to Authentication method and select Login using your Identity Provider.

    gz_authentication_your_idp_cp_en.png

    Note

    This option is available after GravityZone Control Center SSO with an external identity provider has been configured at the company level.

  5. Click Save.

Test Bitdefender services SSO

After configuring both the identity provider and GravityZone, you can test single sign-on as follows:

  1. Log out from any Bitdefender services.

  2. Log out from Microsoft Entra ID/Microsoft 365.

  3. Open MDR portal in a browser.

  4. You should be redirected to GravityZone IdP Proxy, which will redirect you to the Microsoft login page.

  5. Authenticate with your identity provider.

    You will be redirected back to MDR portal and granted access.

Note

GravityZone IdP Proxy does not support IdP-initiated login, but only service provider initiated login. Therefore, you can test the single sign-on by going directly to the Bitdefender service (for example, MDR portal), not by clicking the application in Microsoft Entra ID.

Disable Bitdefender services SSO

To disable single sign-on for Bitdefender services:

  1. Delete the identity provider metadata URL from the Identity provider metadata URL (IdP Proxy) field in the configuration page of that company.

  2. Click Save and confirm the action.

This does not affect GravityZone Control Center SSO, which remains configured separately.

To re-enable SSO for Bitdefender services, enter again the identity provider metadata URL in the Identity provider metadata URL (IdP Proxy) field and click Save.