Configure LDAP integration

The Service Manager SAML Single Sign-On (SSO) solution requires the identity provider (that is, Microsoft ADFS) to connect with an LDAP directory and authenticate users from it.

Meanwhile, this solution requires Service Manager to integrate with the same LDAP directory to share user account information. When integrated with an LDAP directory, user accounts are synchronized from the LDAP server to Service Manager based on LDAP mapping.

When the user enters credentials on the identity provider (IdP) login page, the IdP returns a SAML response that contains a SAML assertion, which is then redirected to Service Manager. If the assertion is valid, the user is logged into Service Manager. This process requires correct LDAP mapping to be configured on both the Service Manager side and the IdP side.

To configure LDAP integration for SAML SSO, perform the following steps:

  1. Configure the IdP (ADFS) to authenticate users from an LDAP directory. For details, refer to the ADFS documentation.
  2. On the IdP side, map the NameID claim type to the samAccountName LDAP attribute. For detailed steps, see Install and configure the HPE Identity Manager service.
  3. In Service Manager, set up an integration with the same LDAP directory. For details, see Enable an integration to LDAP.

    Note When configuring LDAP mapping, map the name field in the operator table to samAccountName. For details about LDAP mapping, see Define file and field-level mappings to an LDAP server.