Skip to main content

Configuring Bitdefender services single sign-on with Okta

GravityZone supports single sign-on (SSO) for Bitdefender services outside GravityZone Control Center, such as MDR Portal, through the GravityZone IdP Proxy. The IdP Proxy uses SAML 2.0 as authentication standard.

This topic describes how to configure single sign-on for Bitdefender services with Okta. For generic information on configuring other Identity Providers, refer to Configuring Bitdefender services single sign-on with Okta.

Prerequisites and requirements

  • You have an Okta account with administrator privileges to create, activate and assign applications to users.

  • You have a GravityZone Cloud administrator account to manage users, your company and other companies.

  • GravityZone users have Okta accounts with the same email addresses.

  • GravityZone Control Center SSO with Okta is already configured and working. Refer to Configure GravityZone Control Center single sign-on with Okta.

  • Users are configured with the Login using your Identity Provider authentication method in GravityZone account settings.

    Note

    This option is only available after GravityZone Control Center SSO has been configured at the company level.

Configure Okta

Single sign-on for Bitdefender services requires a separate Okta application specifically for the GravityZone IdP Proxy. This is in addition to the existing application used for GravityZone Control Center SSO.

This is how you configure an Okta application for GravityZone IdP Proxy:

Extract the GravityZone IdP Proxy SAML metadata

  1. Log in to Bitdefender GravityZone as an administrator.

  2. Click your user name in the upper-right side of the screen and select My Company or go to the company for which you want to configure the IdP SSO.

  3. Go to the Authentication tab.

    gz_authentication_sso_services_cp_1573151_en.png
  4. Under the Bitdefender services single sign-on section, click the button next to the GravityZone IdP Proxy SAML metadata URL field to copy the metadata URL.

    gz_sso_idp_proxy_metadata_url_field_1573149_en.png
  5. Open the metadata URL in a separate tab of your browser and save the page as a metadata.xml file.

    gz_sso_idp_proxy_metadata_file_1573149_en.png

Keep the metadata.xml file open for reference during the Okta configuration. You will need the Entity ID and Assertion Consumer Service URL values from the metadata.

gz_sso_idp_proxy_metadata_file_opened_1573149_en.png

Create the SAML application

  1. Log in to the Okta Admin Console.

  2. In the left-side menu, go to Applications > Applications.

    sso_gz_services_okta_01_admin_console_cp_1573359_en.png
  3. Click Create App Integration.

    sso_gz_services_okta_02_create_app_cp_1573359_en.png
  4. In the Create a new app integration window, select SAML 2.0 as sign-in method, and click Next.

    sso_gz_services_okta_03_saml_20_cp_1573359_en.png
  5. On the Create SAML Integration page, apply the following configuration:

    1. Under the General Settings tab:

      1. Enter an app name (for example, GravityZone IdP Proxy).

      2. (Optional) Upload a logo image and set your app's visibility.

      3. Click Next.

      sso_gz_services_okta_04_app_name_cp_1573359_en.png
    2. Under Configure SAML, follow the steps below:

      1. Under Single sign-on URL, enter the Assertion Consumer Service URL from the IdP Proxy metadata XML and select the check box for Use this for Recipient URL and Destination URL.

      2. Under Audience URI (SP Entity ID), enter the Entity ID from the IdP Proxy metadata XML.

      3. For Name ID format, select EmailAddress.

      4. For Application username, select Email.

        sso_gz_services_okta_05_configure_saml_cp_1573359_en.png
      5. Click the Show Advanced Settings link.

      6. Apply the following configuration:

        1. For Response, select Signed.

        2. For Assertion Signature, select Signed.

        3. For Signature Algorithm, select RSA-SHA256.

        4. For Digest Algorithm, select SHA256.

        5. For Assertion Encryption, select Unencrypted.

        6. Under Signature Certificate, upload the GravityZone IdP Proxy certificate (certificate.cer).

          To obtain the certificate:

          1. Open the metadata.xml file.

          2. Copy the <X509Certificate>...</X509Certificate> value and paste it into a text editor.

            gz_sso_idp_proxy_metadata_file_certificate_1573149_en.png
          3. Add the following lines at the beginning and end of the file:

            -----BEGIN CERTIFICATE----- 
            ...
            -----END CERTIFICATE-----
            sso_gz_services_okta_06_configure_certificate_cp_1573359_en.png
          4. Save the file you created as certificate.cer.

            sso_gz_services_okta_07_certificate_cp_1573359_en.png
        7. For Authentication context class, select PasswordProtectedTransport.

        8. For Honor Force Authentication, select Yes.

        9. For SAML Issuer ID, leave the default value: http://www.okta.com/${org.externalKey}

        Leave the rest of the fields blank.

        sso_gz_services_okta_08_advanced_settings_cp_1573359_en.png
    3. Click Next.

  6. Under Feedback, select This is an internal app that we have created and click Finish.

    sso_gz_services_okta_09_feedback_cp_1573359_en.png

After finishing the configuration, Okta will redirect you to a page containing details about the application you have created.

sso_gz_services_okta_10_review_app_cp_1573359_en.png

Assign users to the application

  1. In the Okta Admin Console, go to the application you just created.

  2. Go to the Assignments tab.

    sso_gz_services_okta_11_assignments_cp_1573359_en.png
  3. Click Assign and select Assign to People or Assign to Groups.

    sso_gz_services_okta_12_assign_cp_1573359_en.png
  4. Select the relevant users or groups and click Assign for each, then click Done.

    sso_gz_services_okta_13_users_cp_1573359_en.png

Get the Okta metadata URL

  1. In the Okta Admin Console, go to the application you created.

  2. Go to the Sign On tab.

  3. Under the Settings > SAML 2.0 section, find the metadata URL.

    This is the identity provider metadata URL you will need for GravityZone.

  4. Click the Copy button to copy the URL to the clipboard.

    You will paste this URL in the GravityZone console when enabling SSO for the company.

    sso_gz_services_okta_14_metadata_url_app_cp_1573359_en.png
  5. Go to the Applications page in Okta to verify the status of your application. The application must be Active.

Enable SSO for Bitdefender services in GravityZone

After configuring single sign-on in Okta, go to GravityZone Control Center to enable SSO for Bitdefender services.

Enable SSO for your company

This is how you enable SSO for Bitdefender services for your company:

  1. In the upper-right corner of Control Center, click the user icon and then select My Company.

  2. In the Authentication tab, under Bitdefender services single sign-on, enter the identity provider metadata URL in the Identity provider metadata URL (IdP Proxy) field. The other field, reserved for the GravityZone IdP Proxy SAML metadata URL, is non-editable.

    sso_gz_services_okta_15_idp_metadata_url_cp_1573359_en.png
  3. Click Save.

Enable SSO for managed companies

This is how you enable single sign-on for Bitdefender services for a company under your management:

  1. Log in to GravityZone Control Center.

  2. Go to the Companies page from the left side menu.

  3. In the table, click the company's name.

  4. Under Bitdefender services single sign-on, enter the identity provider metadata URL in the Identity provider metadata URL (IdP Proxy) field. The other field, reserved for the GravityZone IdP Proxy SAML metadata URL, is non-editable.

    sso_gz_services_okta_15_idp_metadata_url_cp_1573359_en.png
  5. Click Save.

Verify the authentication method for users

Users must have their authentication method set to Login using your Identity Provider in GravityZone account settings. If GravityZone Control Center SSO is already configured and users are already logging in with your identity provider, no additional changes are needed.

If any users still use GravityZone credentials:

  1. Log in to GravityZone Control Center.

  2. Go to the Accounts page from the left side menu.

  3. In the table, click the user's name.

  4. Under Login Security, go to Authentication method and select Login using your Identity Provider.

    gz_authentication_your_idp_cp_en.png

    Note

    This option is available after GravityZone Control Center SSO with an external identity provider has been configured at the company level.

  5. Click Save.

Test Bitdefender services SSO

After configuring both the identity provider and GravityZone, you can test single sign-on as follows:

  1. Log out from any Bitdefender services.

  2. Log out from Okta.

  3. Open MDR portal in a browser.

  4. You should be redirected to GravityZone IdP Proxy, which will redirect you to Okta's authentication page.

  5. Authenticate with your identity provider.

    You will be redirected back to MDR portal and granted access.

Note

GravityZone IdP Proxy does not support IdP-initiated login, but only service provider initiated login. Therefore, you can test the single sign-on by going directly to the Bitdefender service (for example, MDR Portal), not by clicking the application's logo in Okta.

Disable Bitdefender services SSO

To disable single sign-on for Bitdefender services for your company or for a company under your management:

  1. Delete the identity provider metadata URL from the Identity provider metadata URL (IdP Proxy) field in the configuration page of that company.

  2. Click Save and confirm the action.

This does not affect GravityZone Control Center SSO, which remains configured separately.

To re-enable SSO for Bitdefender services, enter again the identity provider metadata URL in the Identity provider metadata URL (IdP Proxy) field and click Save.