Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

Add Identity Providers

To set up single sign-on (SSO) for the Juniper Mist™ portal, add the identity providers (IdPs) that you want to use to authenticate portal users.

Note:

You need the Super User admin role.

  1. On the left menu of the Juniper Mist portal, select Organization > Admin > Settings.
  2. In the Identity Providers section, click Add IDP.
    Identity Providers Section of the Organization Settings Page
  3. In the Create Identity Provider window:
    1. Enter a name, and then click Add.
    2. For the Name ID Format, select the format that you want to use.
      Most people use the e-mail address for the name ID. If you use a different identifier for your IdP user accounts, select Unspecified.
    3. Copy the ACS URL (Assertion Consumer Service URL), which you'll need to complete the SAML 2.0 integration in your IdP's portal.
      location of the ACS URL field
    4. Keep the Create Identity Provider window open so that you can return to it later in this procedure.
  4. Go to your IdP portal and complete these tasks:
    • Set up the user accounts and roles for the users who will use this intregation to authenticate to Juniper Mist portal.

    • Create a SAML 2.0 SSO integration for Juniper Mist.

      Note:

      If your IdP requires metadata from Juniper Mist, see Obtain Juniper Mist Metadata for SAML 2.0 Integration.

    • Get the following information from the SAML 2.0 SSO integration:

      • Signing Algorithm

      • Issuer

      • SSO URL

    • Download the certificate.

  5. Return to the Create Identity Provider in Juniper Mist, and use the information from the SAML 2.0 SSO integration to complete these fields:
    • Signing Algorithm—Select the same signing algorithm that you selected in your IdP SAML 2.0 integration.

    • Issuer

    • SSO URL

    • Certificate—Open the certificate that you downloaded. Copy the entire text and paste it into this field. Include the BEGIN CERTIFICATE and END CERTIFICATE lines.

    Example:

    This example shows how you would complete the Juniper Mist fields on the left by entering the values from the Microsoft Azure fields on the right.

    Example: Create Identity Provider window and corresponding fields from Azure

  6. Click Save to save the settings and close the window.

Next Steps

  1. Create custom roles corresponding to the IdP roles for your users who will access Juniper Mist through SSO. The user role determines which portal features the user can access. See Create Custom Roles for Single Sign-On Access.

  2. After completing the setup tasks (including custom roles), ensure that your users understand the first-time login process. When they first log in to Juniper Mist, they must connect to Juniper Mist by using the SSO URL or their IdP dashboard. This step is necessary for the first login only, to establish the account as an SSO account. After that, they can use the SSO URL or go to directly to the Juniper Mist portal (manage.mist.com).