This guide provides details about Britive and CyberArk Identity SSO integration.
Configuration Steps
Configuring an Identity Provider on Britive
An identity provider needs to be created in Britive for SSO.
- Log in to the Britive application with administrator privileges. 
- Click on Admin->Identity Management from the navigation menu. 
- Click on the Identity Providers tab. 
- Click on the Add Identity Provider button. 
- Enter name and description. 
- Select Identity Provider Type as SAML. 
- Click Add. A configuration page is displayed. 
Configuring SSO on Britive
- Click on the Edit icon under SSO Provider in the SSO Configuration tab.
- Select Generic from the drop-down list.
- Save the changes by clicking the icon next to the selection.
- Keep note of the URLs listed here, they are required to complete the SSO configuration on the identity provider portal.
Configuring CyberArk Identity for SSO
- Log in to CyberArk User Portal as a CyberArk identity Administrator.
- Navigate to the Admin Portal.
- Navigate to Apps & Widgets -> Web Apps from the sidebar menu and click the Add Web Apps button.
- Click on the Custom tab and add the SAML web app.
- Enter the following on the Settings page:- Add a Name and Description.
- Uncheck the Show in user app list checkbox from the Advanced section.
 
- Enter the following on the Trust page:- Download the Metadata file from the Identity Provider Configuration section.
- Select Manual Configuration under Service Provider Configuration.- Enter the entity ID provided by the IDP created in Britive.
- Enter the Assertion Consumer Service (ACS) URL from IDP created in Britive.
 
 
- Enter the following on the SAML Response page:- Add “email” as the Attribute Name and “LoginUser.Email” as an Attribute value.
 
- Enter the required permissions on the Permissions page.
- Click Save to save the web application.
Configuring SSO metadata on Britive
To complete the SSO configuration, the SAML metadata from the identity provider needs to be imported into the Britive application.
Follow the steps below to complete the SSO configuration:
- Log in to the Britive application with administrator privileges. 
- Click on Admin-> Identity Management. 
- Click on the Identity Providers tab. 
- Click on the required identity provider. 
- Click on Upload SAML Metadata. Browse to the identity provider's SAML metadata that was downloaded during configuration of the identity provider. 
- Upon successful upload, the SAML settings are displayed. 
Bookmark application for IDP-initiated login
- Log in to CyberArk Portal as a CyberArk identity administrator.
- Navigate to Admin Portal -> Apps & Widgets -> Web Apps and click Add web apps button.
- Click on the Custom tab and add the Bookmark app.
- Go to the Application Settings and copy the Initiate SSO URL from the Britive configuration into the URL field.
- Add a Name and Description.
- Go to the Permissions page and add specific roles.
- Save the application.