Logging In With Single Sign-on (SSO Integration)

Overview

Federated authentication allows you to use your preferred OpenID Connect (OIDC) identity provider (IdP) to authenticate with Arctic Wolf web portals. This gives your users a single sign-on (SSO) experience with your existing IdP. Additional login credentials for Arctic Wolf services are not required.

Once your organization has access to Arctic Wolf's Unified Portal, single sign-on for Aurora is configurable by Admin users through the Unified Portal's Federated Authentication screen.

This guide provides instructions for both:

  • New users – setting up federated authentication in the Unified Portal from day one
  • Users who have configured Sevco SSO – migrating off your Sevco SAML (or OIDC) connection and setting up federated authentication in Unified Portal

Setting up a New SSO Connection

Note: Arctic Wolf's federated authentication can only be set up by OIDC identity providers.

If you are a new user and configuring federated authentication for the first time, refer to the article below that corresponds with your identity provider:


Migrating from a Sevco SSO Connection

Note: Arctic Wolf's federated authentication can only be set up by OIDC identity providers. If your existing Sevco SSO is SAML, you'll need to create a new OIDC application in your IdP as part of your migration.

If you are an existing user with a Sevco SSO connection, you will need to configure Arctic Wolf's federated authentication for SSO before disabling your Sevco SSO connection. Do not disable your existing Sevco SSO connection until after all of your users have been migrated to your Arctic Wolf SSO connection.

1. Set up a new OIDC app in your IdP

To start, refer to the article below that corresponds with your identity provider:

2. Perform a Test Login & Verify Organization Membership

Once you've set up your OIDC application in your IdP, remove one user from your old application, then assign them to the new application to test for proper configuration.

Have the user login to confirm that they are able to access Aurora ASM via Arctic Wolf SSO.

3. Migrate Your Remaining Users

Once you have verified that a user has successfully logged in, you can migrate your remaining users.


4. Disable your Sevco SSO Connection

After migrating your remaining users to your new OIDC application in your IdP, disable your legacy Sevco SSO application.