This section describes how to add Trend Micro Email Security as a new application and configure SSO settings on your Okta Admin Console.
-
Navigate to the Admin Console by clicking Admin in
the upper-right corner.
Note:
If you are in the Developer Console, click < > Developer Console in the upper-left corner and then click Classic UI to switch over to the Admin Console.
- In the Admin Console, go to Applications > Applications.
-
Click Add Application, and then
click Create New App.
The Create a New Application Integration screen appears.
- Select Web as the Platform and SAML 2.0 as the Sign on method, and then click Create.
- On the General Settings screen, type a name for Trend Micro Email Security in App name, for example, Trend Micro Email Security End User Console, and click Next.
-
On the Configure SAML screen, specify
the following:
-
Type
https://euc.<domain_name>/uiserver/euc/ssoAssert?cmpID=<unique_identifier>
in Single sign on URL based on your serving
site.
Note:In the preceding and following URLs:
-
Replace <unique_identifier> with a unique identifier. Record the unique identifier, which will be used when you create an SSO profile on the Trend Micro Email Security administrator console.
-
Replace <domain_name> with any of the following based on your location:
-
North America, Latin America and Asia Pacific:
tmes.trendmicro.com
-
Europe and Africa:
tmes.trendmicro.eu
-
Australia and New Zealand:
tmes-anz.trendmicro.com
-
Japan:
tmems-jp.trendmicro.com
-
Singapore:
tmes-sg.trendmicro.com
-
India:
tmes-in.trendmicro.com
-
Middle East (UAE):
tmes-uae.trendmicro.com
-
-
- Select Use this for Recipient URL and Destination URL.
- Type https://euc.<domain_name>/uiserver/euc/ssoLogin in Audience URI (SP Entity ID).
- Select EmailAddress in Name ID format.
- Select Okta username in Application username.
-
(Optional) Click Show Advanced
Settings, specify the following:
This step is required only if you want to configure a logoff URL on the Trend Micro Email Security administrator console. The logoff URL is used to log you off and also terminate the current identity provider logon session.
-
Next to Enable Single Logout, select the Allow application to initiate Single Logout check box.
-
Type https://euc.<domain_name>/uiserver/euc/sloAssert?cmpID=<unique_identifier> in Single Logout URL.
-
Type https://euc.<domain_name>/uiserver/euc/ssoLogout in SP Issuer.
-
Upload the logoff certificate in the Signature Certificate area.
You need to download the logoff certificate from the Trend Micro Email Security administrator console in advance. Go to Administration > End User Management > Logon Methods. Click Add in the Single Sign-on section. On the pop-up screen, locate the Identity Provider Configuration section, select Okta as Identity provider and click Download Logoff Certificate to download the certificate file.
-
Keep the default values for other settings.
-
-
Under ATTRIBUTE STATEMENTS
(OPTIONAL), specify email in
Name, and select
Unspecified in Name
format and user.email in
Value.
Important:
When configuring the identity claim type for an SSO profile on Trend Micro Email Security, make sure you use the attribute name specified here.
-
(Optional) Under GROUP ATTRIBUTE STATEMENTS
(OPTIONAL), specify euc_group in
Name, select
Unspecified in Name
format and specify filter conditions.
Important:
When configuring the group claim type for an SSO profile on the Trend Micro Email Security, make sure you use the group attribute name specified here.
- Click Next.
-
Type
https://euc.<domain_name>/uiserver/euc/ssoAssert?cmpID=<unique_identifier>
in Single sign on URL based on your serving
site.
-
On the Feedback screen, click
I'm an Okta customer adding an internal app, and then
click Finish.
The Sign On tab of your newly created Trend Micro Email Security application appears.
- Click View Setup Instructions, and record the URL in Identity Provider Single Sign-On URL and download the certificate in X.509 Certificate.