The following instructions assist the Identity Provider administrator with the setup of single sign-on (SSO) for Nebula with Microsoft OneLogin. Nebula supports the SAML 2.0 authentication protocol.
Get started
- The email address used for the Nebula account must match the email address used for OneLogin.
- Log in to Nebula and go to Configure > Single Sign-on.
- Log in to your OneLogin with administrator credentials.
Add a new application in OneLogin
- In the OneLogin portal, click ADD APP.
- In the Find Applications search bar, enter "SAML Test Connector (IdP) w/ attr w/ sign response".
- Assign a name to the application. For example: Nebula.
Setup OneLogin SAML Settings
- In the Nebula Single Sign-On page, copy the Assertion Consumer Service URL.
- In OneLogin, go to the Configuration tab.
- Paste in the previously copied Assertion Consumer Service URL into the SAML Consumer URL and ACS URL Validator fields.
- Leave the rest of the fields blank.
- Click the Parameters tab > Add parameter.
- Fill or check the following values:
-
Name: email
Note: "email" must be entered in lowercase. - Value: Email
-
Flags: Check Include in SAML assertion
-
Name: email
- Click SAVE.
- On the Parameters tab, click SAVE to save the application configuration.
Upload OneLogin SSO XML file into Nebula
- Click MORE ACTIONS > SAML Metadata to download the OneLogin metadata XML file.
- Return to the Nebula > Configure > Single Sign-On page.
- Have a Nebula Super Admin perform one of the following:
- Drag the OneLogin metadata XML file to the Upload New Metadata XML square.
or - Click Choose a Different File to locate the metadata XML file path.
- Drag the OneLogin metadata XML file to the Upload New Metadata XML square.
Enable SSO
- Once the metadata is uploaded, toggle on Enable SSO.
- Toggle on Just-In-Time (JIT) Provisioning to automatically create Nebula users if they don't already exist when authenticating through OneLogin.
- Toggle on Service Provider Initiated SSO if you will be accessing Nebula through a tile or button in OneLogin.
- Now the application can be assigned to your Nebula administrators in OneLogin.