CrowdStrike - SSO Configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Crowdstrike using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization
To set up Multi-Pass with CrowdStrike, ensure you meet the following requirements:
- CrowdStrike admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in CrowdStrike are registered in your IdP and have the necessary permissions to access CrowdStrike.
CrowdStrike - SSO Configuration
CrowdStrike uses regional URLs for Entity IDs and ACS endpoints. Confirm your CrowdStrike region and copy the correct values below.
CrowdStrike SAML Values
- Provide Metadata to CrowdStrike
- You will see in the next steps how to get the metadata XML or you can use the link below :
- https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor
CrowdStrike requires a support case. Submit the Multi-Pass IdP Metadata XML file to their team. They will complete the setup and confirm when the integration is active.
- Open Multi-Pass Dashboard
- Select your tenant.
- Go to Integrations, click on Applications
- In the custom section click on SAML
- Fill in the following:
Field | Value |
---|
Client ID | CrowdStrike Entity ID |
Name | CrowdStrike |
Assertion Consumer Service | CrowdStrike ACS URL |
NameID Policy Format | email |
|
- Select Download under Tenant XML Data and save the file locally.
- click Add Integration
- Go to the Advanced Console
- Select Clients and search for "CrowdStrike"
- Select the CrowdStrike Client and review the Advanced Settings below :
General Settings
Field | Value |
---|
Client ID | CrowdStrike Entity ID |
Name | CrowdStrike |
Description | CrowdStrike Falcon SSO Integration |
Always display in UI | ON |
Access Settings
SAML Capabilities
Setting | Value |
---|
Name ID Format | email |
Force Name ID Format | ON |
Force POST Binding | ON |
Include AuthnStatement | ON |
Signature & Encryption
Setting | Value |
---|
Sign Documents | OFF |
Sign Assertions | ON |
- Move to the tab "keys" and make sure that both parameters are switched to OFF
- Then move to the "advanced" tab
- Assertion Consumer Service POST Binding URL = Valid redirect URIs = Crowdstrike's ACS URL
CrowdStrike requires a support case. Submit the Multi-Pass IdP Metadata XML file to their team. They will complete the setup and confirm when the integration is active.
Related Articles
SAML SSO Integration Guide
This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
Notion - SSO configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
Vanta - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple ...
Dynatrace - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Dynatrace using MPAS. SSO simplifies user authentication by allowing access to multiple ...
Addigy - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Addigy using MPAS. SSO simplifies user authentication by allowing access to multiple ...