> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-onelogin.md).

# Set up OneLogin SSO on Prisma Cloud

To secure administrator access to Prisma Cloud, set up OneLogin as an IdP and then configure Prisma Cloud as SP for SSO.

If you have selected OneLogin as your Identity and Access Management provider, you can enable single sign-on (SSO) using OneLogin credentials on Prisma Cloud. To enable SSO, you must first complete the setup on OneLogin and then log in with System Administrator privilege on Prisma Cloud to configure SSO and redirect login requests to the OneLogin login page to streamline the log in experience for Prisma Cloud administrative users.

1. Set up OneLogin for SSO.
   1. Before you begin to set up OneLogin configuration, log in to your Prisma Cloud instance, select **Settings > SSO** and copy the Audience URI (SP Entity ID). For example: <https://app.prismacloud.io/settings/sso>.

      <figure><img src="/files/c2WBGLryxsywlb7VZkxx" alt="sso onelogin 01"><figcaption></figcaption></figure>
   2. Log in to OneLogin as an Administrator and click **Administration**.
   3. Select **Applications > Add App**.
   4. Enter **SAML** in the search bar and from the options displayed select **SAML Custom Connector (Advanced)** that is provided by OneLogin, Inc.

      <figure><img src="/files/wxJUcnOLuChHcTmGyLDJ" alt="sso onelogin 1"><figcaption></figcaption></figure>
   5. Enter a Display Name for your application, a description (optional), and click **Save**.

      <figure><img src="/files/7eYNaBP2Vc7rjOn9QXnv" alt="sso onelogin 2"><figcaption></figcaption></figure>
   6. Select **SSO** from the side navigation bar and copy the following values:

      <figure><img src="/files/yoZiXjnGU4Zfk0oDRj80" alt="sso onelogin 3"><figcaption></figcaption></figure>

      * **Issuer URL**
      * **SAML 2.0 Endpoint (HTTP)**
      * **SLO Endpoint (HTTP)**
      * Under **Certificate**, click **View Details** and copy the certificate information.

        <figure><img src="/files/oIjOb8sRpPpnn6Iz6MjF" alt="sso onelogin 4"><figcaption></figcaption></figure>
   7. Select **Configuration**, and enter the following values:

      <figure><img src="/files/aWCX4NrCwLkD7o6KR7Bj" alt="sso onelogin 5"><figcaption></figcaption></figure>

      * **Audience (EntityID)**—Enter the Audience URI (SP Entity ID) value you copied in Step 1 above.
      * **ACS (Consumer) URL Validator**—Enter **.**\*. It is recommended to provide a regular expression-based URL validator. See [Custom Connector Configuration Page](https://onelogin.service-now.com/support?id=kb_article\&sys_id=912bb23edbde7810fe39dde7489619de\&kb_category=93e869b0db185340d5505eea4b961934) for more information.
      * **ACS (Consumer) URL**—Enter your Prisma Cloud URL, however, replace app with api and add saml at the end. For example, if you access Prisma Cloud at <https://app.prismacloud.io>, enter <https://api.prismacloud.io/saml>.
      * **Recipient**—Enter the same value you entered for the ACS (Consumer) URL.
      * **SAML Signature Element**—Select **Assertion** or **Both**.
   8. Click **Save** to save the updated Configuration.
2. Configure SSO on Prisma Cloud.
   1. Log in to Prisma Cloud and select **Settings > SSO**.
   2. **Enable SSO**.
   3. Paste the values you copied in Step 6 above.
      * **Identity Provider Issuer**—Enter the **Issuer URL** value.
      * **Certificate**—Enter the **Certificate** value in the standard X.509 format.
      * tt:\[(Optional)] **Identity Provider Logout URL**—Enter the **SAML 2.0 Endpoint (HTTP)** value to which a user is redirected to, when Prisma Cloud times out or when the user logs out.
   4. **Relay State Param name** is SAML specific Relay State parameter name. If you provide this parameter along with Prisma Cloud Access SAML URL, all notification links in Splunk, Slack, SQS, email, and reports can link directly to the Prisma Cloud application. The relay state parameter or value is specific to your Identity Provider.

      When using RelayState functionality, make sure your Prisma Cloud Access SAML URL corresponds to Identity Provider Single Sign-On URL ending in ‘/sso/saml’.
   5. tt:\[(Optional)] Clear the **Enforce DNS Resolution for Prisma Cloud Access SAML URL**.

      By default, Prisma Cloud performs a DNS look up to resolve the Prisma Cloud SAML Access URL you entered earlier. If your IdP is on your internal network, and you do not need to perform a DNS look up, you can clear this option to bypass the DNS lookup.

      <figure><img src="/files/7bf6i3cBwJl8YJrbJpMs" alt="sso onelogin 7"><figcaption></figcaption></figure>
   6. tt:\[(Optional)]Enable setup-jit-on-onelogin.xml\[Just in Time (JIT) Provisioning] for SSO users.

      **Enable JIT Provisioning**, if you want to create a local account for users who are authenticated by OneLogin. With JIT, the user is provisioned with the first five roles mapped to the user’s profile on OneLogin.
   7. You must provide the email, role, first name, and last name for each user. Timezone is optional.
   8. Select **Allow select users to authenticate directly with Prisma Cloud** to configure some users to access Prisma Cloud directly using their email address and password registered with Prisma Cloud, in addition to logging in via the SSO provider.

      When you enable SSO, make sure to select a few users who can also access Prisma Cloud directly using the email and password that is registered locally on Prisma Cloud to ensure that you are not locked out of the console in the event you have misconfigured SSO and need to modify the IdP settings. For accessing data through APIs, you need to authenticate directly to Prisma Cloud.
   9. Select the **Users** who can access Prisma Cloud either using local authentication credentials on Prisma Cloud or using SSO.

      The users listed in the allow list can log in using SSO and also using a local account username and password that you have created on Prisma Cloud.

      <figure><img src="/files/kiEiVaEDv94dM3dJjPVs" alt="sso onelogin 8"><figcaption></figcaption></figure>
   10. **Save** your changes.
   11. Verify access using SSO.

       Administrative users for whom you have enabled SSO, must access Prisma Cloud from the Identity Provider’s portal. For example, once you have integrated Prisma Cloud with OneLogin, administrative users must login to OneLogin and then click on the Prisma Cloud application name (configured in Step 1) displayed on the dashboard to be logged in to Prisma Cloud.
   12. Using **Last 5 SAML Failures**, you can see details of last five login issues or errors for SSO authentication for any users.

       <figure><img src="/files/3CzNqEbnVfzmSmp7Fjh4" alt="sso onelogin 9"><figcaption></figcaption></figure>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/administration/setup-sso-integration-on-prisma-cloud/get-started-with-saml-sso/setup-sso-integration-on-prisma-cloud-for-onelogin.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
