Skip to main content
Druva Documentation

How to configure SSO for Druva Cloud Platform using Azure AD as IdP

This article applies to:

  • Product edition: Druva Cloud Platform (DCP)

Overview

This article describes the steps to configure SSO for Druva Cloud Platform ( DCP ) using the IDP Azure AD.

Configuration steps:

  1. Configure Druva app for DCP on Azure Portal
  2. Configure Azure AD Single Sign-On
  3. Configure DCP to use Azure AD login
  4. Assign Users/Groups in Azure AD to use DCP app
  5. Enable SSO for administrators
  6. Enable SSO for Users

 

 

 

  • Only a Druva Cloud administrator can set up Single Sign-on. 
  • Configure Single Sign-on based on the applicable scenarios:
    • New inSync customers (on-boarded after July 14, 2018) must configure Single Sign-on using the Druva Cloud Platform Console. For more information, see Set up Single sign-on.
    • Existing inSync customers who have not configured Single Sign-on until July 14th, 2018, must configure Single Sign-on using the Druva Cloud Platform Console. For more information, see Set up Single sign-on

 

Configure a custom app for DCP on Azure portal

To configure a custom app:

  1. Login to the Azure portal (URL: portal.azure.com) with the Azure Administrator account credentials.
  2. Navigate to Azure Active Directory > Enterprise Applications.

    SSOAzureAsIdP01.png
  3. On the Enterprise applications page, click New application.

    SSOAzureAsIdP02.png
     
  4. Search for the application name Druva in the search bar as shown below.

    SSOAzureAsIdP03.png
  5. Select Druva application from the search output list and click Add.

    SSOAddApp.png

    Note: The name of the application can be modified as required. For example, Druva or Druva Cloud Platform.
     
  6. After adding the application, go to Enterprise Application  and select Druva application from the list.
  7. Go to Manage > Properties.  To identify the application distinctly, upload an image here and click Save when done.


    SSOAzureAsIdP05.png


    SSOAzureAsIdP06.png

Configure Azure AD Single Sign-On

To configure Azure AD SSO:

  1. On the Druva application integration page of the Azure portal, click Single sign-on.
  2. On the Single sign-on window, set Mode as SAML-based Sign-on to enable the single sign-on.

    SSOAzureAsIdP07.png
  3. Under the Basic SAML Configuration section, you can see two parameters - auto-filed Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL).
  4. Click Edit and make sure that you have selected the below parameters as default and save the changes.
    Identifier: DCP-login
    Reply URL (Assertion Consumer Service URL): https://login.druva.com/api/commonlogin/samlconsume

    SSOBasicSAMLConfig.png
  5. Click Save once done.
  6. Under User Attributes & Claims, click Edit.

    SSOAzureAsIdP09.png
  7. You can choose to delete all the attributes added by default as Druva Cloud Platform does not use these attributes for authentication.

    SSOAzureAsIdP10.png

    Note : You cannot delete Claim name : http://schemas.xmlsoap.org/ws/2005/0...nameidentifier as this is the mandatory claim for the name identifier.
  8. Click Add New Claim and enter the attributes described in the table below. Preserve the order and case of the attribute name when you enter the names.
    Attribute name Value
    emailAddress user.email

    druva_auth_token

    SSO Token generated from DCP Admin Console, without quotation marks.
    For example: X-XXXXX-XXXX-S-A-M-P-L-E+TXOXKXEXNX=

    Azure automatically adds quotation marks around the auth token.

    SSOAzureAsIdP11.png


    SSOAzureAsIdP12.png


    The final User Attributes & Claims appears as shown below:
    SSOAzureAsIdP13.png
  9. On the SAML Signing Certificate section, click Certificate (Base64) and save the certificate file (Druva.cer) locally.

  10. Under Set up Druva section, copy the Login URL to a notepad/textEditor/Wordpad for future use.

    Sample of ‘Login URL’ : https://login.microsoftonline.com/xx...xxxxxxxx/saml2

Configure DCP to use Azure AD login

Only a Druva Cloud administrator can set up Single Sign-on.

To configure SSO on Druva:

  1. Open a new browser window and login to DCP Management Console
  2. ( https://console.druva.com/admin ) as an Administrator.
  3. Click on the Druva logo on top left corner and then click Druva Cloud Settings.

    SSOAzureAsIdP14.png
  4. On the Single Sign-On tab, click Edit.

    SSOAzureAsIdP15.png
  5. Copy the Login URL obtained from point no. 10 earlier ( https://login.microsoftonline.com/xx...xxxxxxxx/saml2 ) to the ID Provider Login URL field.
  6. Open the Certificate (Base64) downloaded earlier (Druva.cer) in notepad (obtained from point no 9) and copy all the content in ID Provider Certificate field.

    SSOAzureAsIdP16.png
  7. Click Save.

 Assign Users/Groups in Azure AD to use DCP app

  1. On the Azure portal, navigate to Enterprise applications > All applications, select Druva applicaiton created during initial configuraiton from the applications list.
  2. Click Users and groups.

    SSOAzureAsIdP17.png
  3. Click Add User.

    SSOAzureAsIdP18.png
  4. Select Users and groups on the Add Assignment window.

    SSOAzureAsIdP19.png
  5. On the Users and groups window, select the Users or Group that you want to assign the Druva App in the Users list.
  6. Ensure that the User or Admin account selected has a corresponding account created in Druva Cloud Platform.
  7. Click Select on Users and groups window.
  8. Click Assign on Add Assignment window.

Enable SSO for administrators

  1. On the DCP console, go to Druva Cloud Settings.

    SSOAzureAsIdP20.png
  2. On the Single Sign-On section, click Edit.

    SSOAzureAsIdP21.png
  3. Select Administrators log into Druva Cloud through SSO provider.

    SSOAzureAsIdP22.png
    Druva recommends to enable Failsafe for Administrators so that they have to access the DCP console in case of any failures in IdP. It also enables the administrators to use both SSO and DCP password to access the DCP console.
  4. Click Save. This enables the access to Druva Cloud Platform using SSO.

Enable SSO for users

This section applies for inSync users. If you intend to use SSO for Druva Phoenix, please skip this section.

To enable SSO for users, enable SSO for an existing user profile. Alternatively, create a new profile and enable SSO for this profile. Subsequently, assign the users to this profile to enable access using SSO.

Step-1: Create a new profile or update an existing profile:

Step-2: Assign users to the profile:

To assign uses to the profile with SSO enabled, follow the steps described in Update the profile assigned to users.