This configuration workflow explains how to enable single sign-on (SSO) for Qumulo Nexus from the perspective of a system administrator who manages both a Qumulo Nexus account and an Identity Provider (IdP).

After the system administrator performs the initial configuration in Nexus, she must configure the IdP. Then, she can complete the SSO configuration in Nexus.

Prerequisites

  • Administrative access to your organization’s Nexus account

  • A subdomain for your organization

Step 1: Perform Initial Single Sign-On (SSO) Configuration in Qumulo Nexus

Before you can configure the identity provider (IdP), you must perform the initial SSO configuration in Qumulo Nexus.

To Perform Initial SSO Configuration in Nexus

  1. Log in to Qumulo Nexus.

  2. In the upper-right corner, click your username and then click Organization Settings.

  3. On your organization’s page, click SAML SSO, and then click Configure SSO.

  4. On the Configure SAML SSO page, enter a Nexus login subdomain and then click Save & Continue.

    The Entity ID (your Nexus account’s unique identifier) and ACS URL (the Assertion Consumer Service URL that receives SAML responses) are displayed. For example:

    https://mysubdomain.nexus.qumulo.com https://mysubdomain.nexus.qumulo.com/api/v1/auth/saml/acs/

Step 2: Configure an Identity Provider (IdP) for Qumulo Nexus

After you perform the initial SSO configuration in Nexus, you must configure your IdP.

To Configure Your IdP for Nexus

  1. Log in to your IdP’s console.

  2. In the application or service configuration section, take the following steps:

    1. Add Qumulo Nexus as a service provider by using the Entity ID and ACS URL from your Nexus account.

    2. Map the IdP attributes for user email, first name, and last name to the email, firstName, and lastName Nexus attributes.

For more information specific to your SAML IdP, see the following documentation:

Step 3: Perform Final Single Sign-On (SSO) Configuration in Qumulo Nexus

After you configure the identity provider (IdP), you must perform the final SSO configuration in Qumulo Nexus by using the IdP Metadata URL provided by your system administrator.

  1. Log in to Qumulo Nexus.

  2. In the upper-right corner, click your username and then click Organization Settings.

  3. On your organization’s page, click SAML SSO, and then click Configure SSO.

  4. On the Configure SAML SSO, enter the the IdP Metadata URL provided by your system administrator and then click Complete Configuration.

    SAML SSO - Enabled is displayed.

Next Steps

After you perform the final SSO configuration, you can click Users and then add users to your Nexus account. Every user that you add has SSO enabled by default.