Enabling User Management with Active Directory and Active Directory Federation Services

ThreatStream provides the capability to integrate with Microsoft Active Directory Federation Services (ADFS), thus enabling single sign-on (SSO) and ThreatStream user administration from Microsoft Active Directory (AD) or Azure AD.

Notes:
  • After you configure SSO and use an IDP for user management, user accounts are automatically created on ThreatStream when users authenticate to ThreatStream from your IDP for the first time.

Requirements

  • The integration supports the following platforms:

    • Windows Server 2019 with an AD on Server 2019
    • Windows Server 2016 with an AD on Server 2016

      Note: Windows Server platforms must have an active ADFS service configured. Windows Server 2012 is not supported.

    • Azure AD with an Azure AD Directory Services environment
  • You must have an active SAML 2.0 configuration on ThreatStream. Contact Anomali Support for assistance.

Configuring Integration with ADFS and AD

Configuring the integration is a process, which consists of several steps. See the table below to learn about the steps required for the integration of ThreatStream with ADFS and AD.

Microsoft AD Azure AD
1. Configuring the Integration on Microsoft AD 1. Configuring the Integration on Azure AD
2. Creating the Transform Claim Rules in ADFS 2. Enabling the Integration on ThreatStream
3. Enabling the Integration on ThreatStream  

Configuring the Integration on Microsoft AD

Note: These instructions pertain to Microsoft AD only. If you use Azure AD, see Configuring the Integration on Azure AD.

Configuring the integration on Microsoft AD involves creating groups corresponding to each permission in ThreatStream and one additional group which grants users access to ThreatStream. The table below lists all required permissions and the default group names recognized by ThreatStream. Groups can be given any name and mapped to their corresponding ThreatStream permission in a later step. However, if you use the default values, mapping is automatic.

Default AD Group Name ThreatStream Permission
SecGrp_TSAdminUser Org Admin
SecGrp_TSAuditor Can Audit
SecGrp_TSChangeRules Can Use Rules
SecGrp_TSChatUser Can Use Chat
SecGrp_TSCreateCommunityIntelUser Create Anomali Community Intel
SecGrp_TSIntelApprover Approve Intel
SecGrp_TSReadOnlyUser Read Only Account
SecGrp_TSSubmitSandbox Submit Sandbox
SecGrp_TSTaxiiUser Import to TAXII Feeds

SecGrp_TSUseMatch

Note:  

You must configure the group for the Can use Security Analytics permission:

  • To control user access to Security Analytics, if your organization is subscribed to Anomali Security Analytics.

  • To control user access to AQL-based dashboards. For more information on AQL-based dashboards, visit the Anomali Dashboards Help Center.

Can use Security Analytics

SecGrp_TSUser

Note: All users must be part of the SecGrp_TSUser group.

ThreatStream User

SecGrp_TSViewAPIKeyUser Show API Key for Users

To create groups in Microsoft AD:

  1. Right-click in the AD window and select New > Group.

  2. Enter a Group name for the new group. Refer to the table above for the default group name values recognized by ThreatStream or enter a non-default value.

  3. Under Group Scope, select Global.
  4. Under Group Type, select Security.
  5. Click OK. The group is created.

Repeat this process for each permission listed in the table above. After creating each group, you can add desired permissions to each ThreatStream user in AD. These permissions will be synchronized with ThreatStream the next time the user logs in to ThreatStream.

When configuration on Microsoft AD is complete, proceed to Creating the Transform Claim Rules in ADFS to continue configuring the integration.

Creating the Transform Claim Rules in ADFS

To export groups from Microsoft AD to ThreatStream, you must configure a Transform Claim Rule for each ThreatStream related group you created in Microsoft AD.

Note: This section pertains to Microsoft AD users only. No configuration in ADFS is required for Azure AD users.

To create transform claim rules in ADFS:

  1. From ADFS, open the Relying Party Trusts directory.
  2. Right-click the Relying Party Trust associated with ThreatStream and select Edit Claim Issuance Policy.

  3. If the following rules of the Send LDAP Attributes as Claims template type are configured on your system, proceed to step 4:

    • Get LDAP attributes as claims

    • Email to Name ID

      Otherwise, click the link below and follow the instructions provided.

  4. In the Edit Claim Issuance Policy dialog box, click Add Rule to create a rule for an AD group.

  5. Select Send Group Membership as a Claim from the Claim rule template drop-down list.

  6. In the corresponding field, enter a claim rule name for the rule. Anomali recommends using the name of the AD group for which you are creating the rule.

  7. Under User's group, click Browse and select the prior created AD group for which you are creating the rule.
  8. Under Outgoing claim value, enter the exact value of the AD group name for which you are creating the rule.
  9. Click Finish.

Repeat this process described for the Send Group Membership as a Claim template for each ThreatStream permission you created in AD. After adding rules for each group, proceed to Enabling the Integration on ThreatStream to complete configuration within ThreatStream.

Configuring the Integration on Azure AD

If you use Azure AD, you can use the instructions in this section to complete the Azure AD configuration steps. ThreatStream supports the mapping of permissions in ThreatStream to Azure AD Groups. You can use these groups in your Azure environment to manage user access or permissions inside the ThreatStream application.

Note: These instructions pertain to Azure AD only. If you use Microsoft AD, see Configuring the Integration on Microsoft AD.

To configure the integration on Azure AD:

  1. Create a Non-Gallery Enterprise Application for ThreatStream.

    1. Within Azure AD, click Enterprise applications under Manage in the left menu.
    2. Click New Application.
    3. Under Add your own app, click Non-gallery application.
    4. Enter a Name for the application.

      Recommended value: ThreatStream

    5. Set Assignment required? to No.

    6. Click Add. The application is created. You are directed to the Overview screen of the application.
  2. Enable SAML for the application.

    1. From the Overview screen of the ThreatStream application, click 2. Set up single sign on.
    2. Under Select a single sign on method, click SAML.
    3. In the Basic SAML Configuration box, click Edit.
    4. Under Identifier (Entity ID), enter an ID for the SAML configuration.

      Anomali recommends using the ThreatStream API URL: https://optic.threatstream.com

    5. Enter the following Reply URL:

      https://optic.threatstream.com/api/v1/saml2/<idp-name>/acs/

      where <idp-name> is the name of your identity provider (IDP). See Configuring an Identity Provider for SSO for more information.

    6. Click Save.
  3. Add a Claim for the SAML configuration.

    1. In the User Attributes & Claims box, click Edit.
    2. Click Add new claim.
    3. Enter a Name for the claim.

      Required value: emailaddress

    4. Enter the following Namespace value:

      http://schemas.xmlsoap.org/ws/2005/05/identity/claims

    5. For Source, select Attribute.
    6. For Attribute, select user.mail.
    7. Click Save.
  4. Add a Group Claim for the SAML configuration.

    1. On the User Attributes & Claims screen, click Add a group claim.
    2. Under Which groups associated with the user should be returned in the claim?, select Security Group.
    3. For Source attribute, select Group ID.
    4. Select Customize the name of the group claim.
    5. Select Emit groups as role claims.
    6. Click Save.
    Anomali recommends adding a filter to the claim to only send ThreatStream groups. Alternatively, ensure that the ThreatStream groups are not dropped from the claim due to exceeding the maximum number of groups in a claim.
  5. Collect your SAML Signing Certificate, Login URL, and Azure AD identifier. You will use this information when configuring your identity provider in ThreatStream. To locate this information:

    1. From the SAML-based Sign-on screen for the application, locate the SAML Signing Certificate box. Next to Certificate (base 64), click Download.
    2. Locate the Set up <application name> box. Note the Login URL (also known as SAML Single Sign-On Service URL) and Azure AD Identifier (also known as SAML Entity ID) values.
  6. Create a group in Azure AD corresponding to each permission in ThreatStream, as well as one additional group that grants users access to ThreatStream. The table below lists all required permissions and the default group names recognized by ThreatStream. Groups can be given any name and mapped to their corresponding ThreatStream permission in a later step. However, if you use the default values, the mapping is automatic.

    Default AD Group Name ThreatStream Permission
    SecGrp_TSAdminUser Org Admin
    SecGrp_TSAuditor Can Audit
    SecGrp_TSChangeRules Can Use Rules
    SecGrp_TSChatUser Can Use Chat
    SecGrp_TSCreateCommunityIntelUser Create Anomali Community Intel
    SecGrp_TSIntelApprover Approve Intel
    SecGrp_TSReadOnlyUser Read Only Account
    SecGrp_TSSubmitSandbox Submit Sandbox
    SecGrp_TSTaxiiUser Import to TAXII Feeds

    SecGrp_TSUseMatch

    Note:  

    You must configure the group for the Can use Security Analytics permission:

    • To control user access to Security Analytics, if your organization is subscribed to Anomali Security Analytics.

    • To control user access to AQL-based dashboards. For more information on AQL-based dashboards, visit the Anomali Dashboards Help Center.

    Can use Security Analytics

    SecGrp_TSUser

    Note: All users must be part of the SecGrp_TSUser group.

    ThreatStream User

    SecGrp_TSViewAPIKeyUser Show API Key for Users

    To add groups in Azure AD:

    1. From the Azure Active Directory Overview screen, click Groups under Manage in the left menu.
    2. Click New Group.
    3. Under Group type, select Security.
    4. Under Group name, enter the name of the permission.
    5. Click Create. The group is created.

      Repeat this process for each permission listed above.

      Note: The newly created security groups must be assigned to the proper Enterprise application (ThreatStream) to be visible when the application calls for the permissions.

      After creating each group, you can add desired permissions to each ThreatStream user in AD. These permissions will be synchronized to ThreatStream the next time the user logs in to ThreatStream.

      Note the Object ID values for each permission you created. You will use these IDs to finish configuring the integration within ThreatStream in a later step.

      When configuration on Azure AD is complete, proceed to Enabling the Integration on ThreatStream to complete configuration within ThreatStream.

Enabling the Integration on ThreatStream

To finish configuring the integration, you must configure a Break Glass account and map the groups created in Microsoft or Azure AD onto their corresponding permissions in ThreatStream.

Note: You must use a ThreatStream account with the Org Admin permission in order to complete the steps in this section.

To enable the integration on ThreatStream:

  1. In the bottom-left corner of the side navigation panel, click > ThreatStream and then click SSO.

  2. Select a user account that will serve as the Break Glass Account and click Update.

    Notes: 
    • Only Org Admin users are available in the drop-down list.

    • The Break Glass Account should be an independent, local account on ThreatStream. Another account with the same configuration must not exist in the SSO IDP. Doing so will cause login failures. See Managing Organization Users to learn how to create a local account on ThreatStream.

  3. (Recommended) Enable the Use SSO for login exclusively if you want to prevent users from logging in through the ThreatStream login page.
  4. Add an identity provider, as described in Configuring an Identity Provider for SSO.
  5. After the identity provider is configured, specify ADFS or Azure AD under Permission management.

  6. If you selected ADFS, you must specify the Group Name corresponding to each permission. If you used the Default AD Group Name values, the Group Names are automatically mapped to the correct permission. If you used non-default names, click the first permission in the list. Specify the correct Group name in the Edit SSO Permission Mapping window and click Save.

    Repeat this process for each permission.

    If you selected Azure AD, you must specify the Group IDs corresponding to each permission. You noted the Group IDs in the final step of the Azure AD configuration process. To do so, click the first permission in the list. Specify the correct Group ID in the Edit SSO Permission Mapping window and click Save.

    Repeat this process for each permission.

Configuration is complete and your integration is now active.