Enabling User Management with Third-Party Identity Providers
Anomali provides the capability to integrate with third-party identity providers, thus enabling single sign-on (SSO) and user administration from these services. Third-party identity providers include:
-
Microsoft Active Directory Federation Services (ADFS). See Enabling User Management with Active Directory Federation Services and Azure Entra ID for more information.
-
Other SAML 2.0-compliant IdP services. See for Enabling User Management with SAML 2.0 IdP Services for more information.
Additionally, you can configure the integration to force all Anomali users in your organization to connect to the Anomali platform through AD or SAML 2.0 IdP using SSO.
Organizations that configure the integration are given one Break Glass Account user, which maintains access to the Anomali platform user interface through the login page in the event when access through AD or SAML 2.0 IdP is unavailable. Break Glass Account users cannot log in to the Anomali platform using SSO.
For instructions on how to set up SSO and user management with AD and ADFS, see Enabling User Management with Active Directory Federation Services and Azure Entra ID.
For instructions on how to set up SSO and user management with SAML 2.0 IdPs, see Enabling User Management with SAML 2.0 IdP Services.
Managing Organization Users from Third-Party IDP Services
After configuring the integration, organization administrators can perform all user administration tasks, including the creation of new users and assigning of roles, from AD or SAML 2.0 IdP without connecting to the Anomali platform user interface. During configuration, organization administrators define security groups in the IdP in their organization and map them to roles. When organization administrators grant or revoke privileges for a user from an IdP, these updates are synchronized with the Anomali platform through ADFS or SAML 2.0 IdP the next time the user logs in to the platform.
Administrators should note the following when managing organization users from a third-party IdP:
-
All roles and their respective permissions are disabled. When you log in to the Anomali Platform through a third-party IdP, all roles become disabled. In this case, role management must be done through the third-party IdP you use to log in to the Anomali platform.
-
If you assign a user role with the Read Only permission, all other roles and permissions become unavailable. Thus, if you assign a user the Read Only role and a restricted role such as the "Intelligence Approver" role, the restricted permission you assigned to the user is ignored.
-
There is no mechanism to delete users through an IdP. Thus, you must delete users from both the IDP and the Anomali platform to fully remove them. For information on removing users from the Anomali platform, see Deactivating a User. While you cannot delete users through an IdP, users can be prevented from accessing the Anomali platform by disabling them in the IdP.