Configure Microsoft Entra ID as a SAML (2.0) identity provider for Trend Vision One to use.
Microsoft Entra ID is a multi-tenant cloud based directory
and identity management service.
To use Microsoft Entra ID as an identity provider (IdP), you
must have a valid subscription with a Microsoft Entra ID
edition license (Free, Basic, or Premium) that handles the sign-in process and
provides authentication credentials to the Trend Vision One management console.
Procedure
- Create a new enterprise application in the Microsoft Entra ID console.
- Sign in to the Microsoft Azure portal using your Microsoft Entra ID administrator account.
- Under Azure services, click Microsoft
Entra ID.On first use, you might need to click More services and search for Microsoft Entra ID.
- In the left navigation bar, go to .
- Click + New application.
- On the Browse Microsoft Entra Gallery screen,
click + Create your own application.The Create your own application window appears.
- Specify a display name for the application.
- Under What are you looking to do with your application?, select Integrate any other application you don't find in the gallery (Non-gallery).
- Click Create.The Overview screen for the application appears.
- Assign users and roles to the application.
Important
If you intend to use the Private Access and Internet Access services in Zero Trust Secure Access, Trend Micro recommends skipping this step. Instead, go to in the left navigation bar, use the toggle to disable Assignment required? toggle, click Save, and then go on to Step 3.If user assignment is required, assign each user individually to use the Private Access service and Internet Access service.- Under Getting Started, click the link in the 1. Assign users and groups section.
- Click + Add user/group.
- Under Users and groups in the left navigation bar, click None Selected.
- Select or search for the users you want to assign, and then click Select.
- When you have finished selecting users, click Assign.
- Click Assign.The selected users appear on the Users and groups screenfor the application.
- Configure single sign-on for the application.
- Go to Overview in the left navigation bar.
- Under Getting Started, click the link in the 2. Set up single sign on section.
- Under Select a single sign-on method, click SAML.
- Click Upload metadata file.
- Click Select a file and select the metadata XML
file downloaded from Identity Providers in the Trend Vision One console.For more information on obtaining the Trend Vision One metadata file, see Identity Providers (Foundation Services release).
- Click Add to upload the file.The Basic SAML Configuration window appears automatically.
- Click Save and close the Basic SAML Configuration window.
- (Optional) Configure attributes and claims to support IdP-Only SAML Group
Accounts.
- In the Attributes & Claims section, click
Edit.The Attributes & Claims screen appears.
- For Unique User Identifier (Name ID), ensure that the default value is user.userprincipalname.
- Click + Add a group claim to grant selected groups access to Trend Vision One.
- Based on the users you assigned to the application, select the most
suitable option.For more information on selecting groups, see Microsoft Entra ID documentation.
- For Source attribute, use the default value Group ID.
- Click Save.Be sure to copy and retain the Group ID claim name to specify as the Group attribute in the Trend Vision One Identity Providers app.
- (Optional) Click + Add new claim, specify
name in the Name field
and select an attribute for the Source attribute
field, then click Save.Trend Micro recommends skipping this step unless you want to use an attribute other than the default, user.userprincipalname, to distinguish different users. By default, users are distinguished by their NameID.If you choose to complete this step, be sure to copy and retain this claim name to specify as the User attribute in the Trend Vision One Identity Providers app.
- Click + Add new claim, specify
displayname in the
Name field and
user.displayname in the Source
attribute field, and click
Save.Be sure to copy and retain this claim name to specify as the User display name attribute in the Trend Vision One Identity Providers app.
- Click SAML-based Sign-on to return to the previous screen.
- If prompted to test single sign-on with the new application, click No, I'll test later.
- In the Attributes & Claims section, click
Edit.
- In the SAML Certificates section, click Download to obtain the Federation Metadata XML file.
- In the Trend Vision One console, add Microsoft Entra ID as an identity provider and import
the downloaded metadata file.For more information on adding identity providers to Trend Vision One, see Identity Providers (Foundation Services release).