{"id":60,"date":"2024-02-23T16:49:41","date_gmt":"2024-02-23T16:49:41","guid":{"rendered":"http:\/\/gigabrit.com\/?p=60"},"modified":"2024-02-23T16:49:42","modified_gmt":"2024-02-23T16:49:42","slug":"building-a-zscaler-lab-part-2-zscaler-and-saml-idp-integration","status":"publish","type":"post","link":"https:\/\/gigabrit.com\/?p=60","title":{"rendered":"Building a Zscaler Lab Part 2 (Zscaler and SAML IdP Integration)"},"content":{"rendered":"\n<p>We&#8217;re getting closer to the real fun where we can start provisioning Application access and Securing traffic with Zscaler. Before we can do that we have some work to do.  <\/p>\n\n\n\n<p>Let&#8217;s connect an Identity Provider (IdP) to our Zscaler Tenant. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"582\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/ZscalerIdPSlide-1024x582.png\" alt=\"\" class=\"wp-image-61\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/ZscalerIdPSlide-1024x582.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/ZscalerIdPSlide-300x170.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/ZscalerIdPSlide-768x436.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/ZscalerIdPSlide.png 1171w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>If you&#8217;ve seen a Zscaler presentation at all , you&#8217;ve probably seen the above image. This effectively maps out the Zero Trust process for Authentication and where it fits in the overall scheme of establishing connections. I&#8217;ve highlighted the piece covered in this post in the slide above. See the official documentation here. <a href=\"https:\/\/help.zscaler.com\/zia\/adding-identity-providers\">https:\/\/help.zscaler.com\/zia\/adding-identity-providers<\/a><\/p>\n\n\n\n<p>  Step 1: Login to your Zscaler Admin Portal for the Cloud your tenant is provisioned on. Assuming you are a customer , partner, or working with your Zscaler team on setting up a PoV test, use the link provided to you. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"516\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-10.54.07\u202fAM-1024x516.png\" alt=\"\" class=\"wp-image-62\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-10.54.07\u202fAM-1024x516.png 1024w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-10.54.07\u202fAM-300x151.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-10.54.07\u202fAM-768x387.png 768w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-10.54.07\u202fAM.png 1292w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>On the Admin page, go to <strong>Administration> Authentication<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"638\" height=\"581\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.02.01\u202fAM.png\" alt=\"\" class=\"wp-image-63\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.02.01\u202fAM.png 638w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.02.01\u202fAM-300x273.png 300w\" sizes=\"auto, (max-width: 638px) 100vw, 638px\" \/><\/figure>\n\n\n\n<p>Then on the &#8220;Identity Providers&#8221; tab, we&#8217;ll select the &#8220;+ Add IdP&#8221; , if you already happen to have one setup, and are prompted with another option, just select &#8220;Add another&#8230;&#8221; and Next. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"838\" height=\"567\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.17.17\u202fAM.png\" alt=\"\" class=\"wp-image-64\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.17.17\u202fAM.png 838w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.17.17\u202fAM-300x203.png 300w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.17.17\u202fAM-768x520.png 768w\" sizes=\"auto, (max-width: 838px) 100vw, 838px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"375\" height=\"218\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.21.14\u202fAM.png\" alt=\"\" class=\"wp-image-65\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.21.14\u202fAM.png 375w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.21.14\u202fAM-300x174.png 300w\" sizes=\"auto, (max-width: 375px) 100vw, 375px\" \/><\/figure>\n\n\n\n<p>On the Add IdP page we&#8217;ll need some of the info we saved from Azure before, if you didn&#8217;t save it you&#8217;ll need to go back into your Azure Tenant and get it. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"699\" height=\"743\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.22.16\u202fAM.png\" alt=\"\" class=\"wp-image-66\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.22.16\u202fAM.png 699w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.22.16\u202fAM-282x300.png 282w\" sizes=\"auto, (max-width: 699px) 100vw, 699px\" \/><\/figure>\n\n\n\n<p>Enter the following required details:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name:\u00a0<strong>Azure<\/strong>\u00a0(or whatever you want)<\/li>\n\n\n\n<li>Status:&nbsp;<strong>Enabled<\/strong><\/li>\n\n\n\n<li>SAML Portal URL:&nbsp;<code>&lt;Paste in Login URL link you saved.&gt;<\/code><\/li>\n\n\n\n<li>Login Name Attribute:&nbsp;<strong>NameID<\/strong>&nbsp;&lt;&#8211; This is case-sensitive.<\/li>\n\n\n\n<li>IdP SAML Certificate:&nbsp;<strong>Upload .pem file you saved from before<\/strong><\/li>\n\n\n\n<li>Vendor:\u00a0<strong>Microsoft Azure Active Directory<\/strong><\/li>\n<\/ul>\n\n\n\n<p>You should end up with an IdP profile that looks something like the following.<\/p>\n\n\n\n<div class=\"wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-ad2f72ca wp-block-group-is-layout-flex\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"700\" height=\"741\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.10\u202fAM-1.png\" alt=\"\" class=\"wp-image-68\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.10\u202fAM-1.png 700w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.10\u202fAM-1-283x300.png 283w\" sizes=\"auto, (max-width: 700px) 100vw, 700px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"699\" height=\"739\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.23\u202fAM.png\" alt=\"\" class=\"wp-image-69\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.23\u202fAM.png 699w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.30.23\u202fAM-284x300.png 284w\" sizes=\"auto, (max-width: 699px) 100vw, 699px\" \/><\/figure>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<p>Now that we&#8217;ve connected our Azure IdP, we need to set Zscaler to use it.  Navigate back to <strong>Administration>Authentication<\/strong> , then just select the SAML Authentication Type. Select Save at the bottom of the page, then be sure to &#8220;Activate&#8221; your changes. <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"586\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.36.06\u202fAM.png\" alt=\"\" class=\"wp-image-70\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.36.06\u202fAM.png 640w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.36.06\u202fAM-300x275.png 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"350\" height=\"458\" src=\"http:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.38.37\u202fAM-1.png\" alt=\"\" class=\"wp-image-72\" srcset=\"https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.38.37\u202fAM-1.png 350w, https:\/\/gigabrit.com\/wp-content\/uploads\/2024\/02\/Screenshot-2024-02-23-at-11.38.37\u202fAM-1-229x300.png 229w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><\/figure>\n\n\n\n<p>That&#8217;s really it for enabling an authentication source. Next Post I&#8217;ll cover off enabling SCIM for updates and changes. <\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We&#8217;re getting closer to the real fun where we can start provisioning Application access and Securing traffic with Zscaler. Before we can do that we have some work to do. Let&#8217;s connect an Identity Provider (IdP) to our Zscaler Tenant. If you&#8217;ve seen a Zscaler presentation at all , you&#8217;ve probably seen the above image. &hellip; <a href=\"https:\/\/gigabrit.com\/?p=60\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Building a Zscaler Lab Part 2 (Zscaler and SAML IdP Integration)<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-60","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/60","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=60"}],"version-history":[{"count":2,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/60\/revisions"}],"predecessor-version":[{"id":74,"href":"https:\/\/gigabrit.com\/index.php?rest_route=\/wp\/v2\/posts\/60\/revisions\/74"}],"wp:attachment":[{"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=60"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=60"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gigabrit.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=60"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}