BitDefender - SSO configuration

BitDefender - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Bitdefender GravityZone using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with Bitdefender GravityZone, ensure you meet the following requirements:
- Bitdefender GravityZone admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Bitdefender GravityZone are registered in your IdP and have the necessary permissions to access Bitdefender GravityZone.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.
Important: Super Admin can't use the SSO, it is a security from BitDefender to always allows one person to reach admin settings in case there is trouble with the SSO




BitDefender - SSO configuration





Step 1 - Configure in Bitdefender GravityZone (Service Provider)

  1. Log in to GravityZone Control Center with admin rights.
  2. On the right side click on the icon called User menu
  3. Click on My Company
  1. Go to the authentication tab and locate the section called Single Sign On using SAML
  1. First, on the line GravityZone SAML metadata URL, click on the icon on the right to copy the URL. 
  1. Paste it in your browser and right click, "save as" to create an XML file.
    1. This file will be uploaded in MPAS
  2. Now you have an empty field called Identity provider metadata URL, paste the link you can find below. 
    1. https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor

Step 2 - Configure in Multi-Pass (Identity Provider)

  1. Open Multi-Pass Dashboard.
  2. Select your tenant.
  3. Go to Integrations and click on Applications.
  4. In the Custom section, choose SAML.
  5. Click on Upload file and use the metadata you gathered from Bitdefender.
  6. It should automatically complete the fields : 
FieldValue
Client IDhttps://gravityzone.bitdefender.com/sp
  Name
 for example "Bitdefender"
  Description
 For example "SSO integration" 
Assertion Consumer Service (ACS) URLhttps://gravityzone.bitdefender.com/sp/login
NameID Policy Formatemail
  1. Click on Add integration
  2. On the left side, click on Advanced console 
  3. Click on client 
  4. Use the search bar to look for bitdefender
  5. We are now going to verify that all the fields are correctly completed :
General settings
SettingValue
Client IDhttps://gravityzone.bitdefender.com/sp
NameBitdefender GravityZone
  Description 
  SSO integration
 Always display in UI
  ON

Access settings
SettingValue
Home URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIshttps://gravityzone.bitdefender.com/sp/login
  Valid post logout redirect URIs
  IDP-Initiated SSO URL name 
  <APP_NAME>

SAML Capabilities
SettingValue
Force Name ID FormatOFF
Force POST BindingON
Include AuthnStatementON

Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON
  • Now that you have checked the different parameters, change to the tab called Keys.
    • You will see both paramaters switched to ON 
  • Now go to the Advanced tab.
  • The field Assertion Consumer Service POST Binding URL must equal the Valid Redirect URIs (ACS).
    • Related Articles

    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Zoho One - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Zoho One using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Vanta - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple ...