Configuring SAML with JIT provisioning

You can configure the just-in-time (JIT) with Security Assertion Markup Language (SAML) for single sign-on (SSO).

To configure SAML with JIT provisions, complete the following steps:

  • Ensure that the users can log in to the IBM Cloud Pak foundational services platform. For more information, see Granting access to capabilities within an IBM Cloud Pak to enable access to the users.
  • You must authenticate to the IBM Cloud Pak foundational services platform to enable the JIT provision in the Cloud Pak platform.
  • Configure SAML with SAML at the identity providers (IdPs) and service provider (SP) ends. For more information, see IBM Cloud Pak JIT support for SCIM OKTA and Entra ID.
  • To search for a user group and add it to the Zen console, at least one user in the group needs to log in and authenticate so that the user group appears in the IBM Cloud Pak access control dashboard group search.
  • If you integrate with SAML with JIT for user onboarding, a user needs to log in to synchronize with the IBM Cloud Pak. Then, an administrator needs to log in with the default cpadmin or admin role and search for the user on the access control dashboard to assign the user's role.
  • If you remove the user or group from a SAML JIT provider, such as OKTA or Microsoft Entra ID, manually remove the user or group from your IBM Cloud Pak.

Example of SAML with JIT configuration

Figure 1. SAML with JIT provisioning
SAML with JIT provisioning

For the SAML with JIT configuration, the users need to authenticate to the IBM Cloud Pak foundational services operator to enable the JIT provision in the foundational services user repository.

After you enable JIT provision in the foundational services user repository, the QRadar Suite uses SCIM to retrieve the users from the foundational services operator.