Azure AD Integration and SSO for Zero Trust Secure Access

Integrate with Azure AD to authenticate user access attempts and take action on risky account activity.

Important:

You cannot configure single sign-on (SSO) from multiple IAMs. Ensure that you configure the necessary permissions and SSO on the IAM you want to use for Private Access and Internet Access authentication.

Operations Dashboard and Zero Trust Secure Access both require the data upload permission to ensure certain features function properly. Turning off the data upload may prevent secure access policy enforcement and risk analysis.

  1. Go to Zero Trust Secure Access > Secure Access Configuration > Identity and Access Management.
  2. To take direct action on risky accounts and authenticate Private Access and Internet Access rules, grant necessary permissions in the Third-Party Integration app.
    1. Click Grant permissions next to Azure AD.

      The Azure AD screen in a new browser tab.

    2. Locate one or multiple Azure AD tenants that you want to grant the "Read directory data and perform account management actions" permissions on, and then click Grant permissions in the Status column for Zero Trust Secure Access.
    3. Follow the onscreen instructions to enable the data connection.
    4. Switch back to the Zero Trust Secure Access browser tab.
    5. Configure your Azure AD SSO settings.
  3. To configure risk control rules, you must also grant data upload permission for Azure AD in Operations Dashboard > Data source.
    1. Go to the Data Source panel in Operations Dashboard by clicking Data Source in the information that displays when you hover over in the Data upload permission status column.
    2. If the required Azure AD permissions are not granted yet, click Manage permissions and integration settings in Third-Party Integration to open the Azure AD screen of the Third-Party Integration app.
    3. Locate the Azure AD tenants that you want to grant permissions on, and then click Grant permissions in the Status column for Risk Insights.
    4. Switch back to the Azure AD Data Source panel and turn on Data upload permission.
    5. Switch back to the Zero Trust Secure Access browser tab.