Configuring Zero Sign-on in Ivanti EPMM
Create a Zero Sign-on configuration in Ivanti EPMM and sync with Ivanti Access.
Before you begin
You have set up Ivanti Access with Ivanti EPMM. See Overview of configuration with Ivanti EPMM.
Procedure: Overview of steps
Creating a Zero Sign-on policy in Ivanti EPMM
In Ivanti EPMM, create a Zero Sign-on policy.
Before you begin
Ensure that you have configured Zero Sign-on in Ivanti Access.
Procedure
- In Ivanti EPMM, go to Policies & Configs > Policies > Add New > SaaS Sign-on.
- In the Name field, enter a name for the configuration.
- For Status, select Active.
Active is default status. - (Optional) Add a description for the policy.
- For Identity Certificate, select the certificate enrollment setting you created for Ivanti Tunnel.
The Ivanti Tunnel certificate is the same certificate you used to set up mobile app single sign-on in Ivanti Access. - Turn on the Enable FIDOtoggle switch to enable FIDO authentication.
- Click Save.
- Apply the policy to a label.
- Select the SaaS sign-on policy.
- Click Actions > Apply To Label.
- Select the labels to apply and click Apply.
- For more information about configuring mobile app single sign-on (SSO):
- For a federated pair, see Configuring Mobile App Single Sign-on (SSO).
- For delegated IdP, see Configuring Ivanti Access as the delegated IdP .
Syncing the Zero Sign-on policy with Ivanti Access
Sync with Ivanti Access to pull the Zero Sign-on configuration from the UEM.
Procedure
- In Ivanti Access, navigate to the UEM tab.
- Select the Ivanti EPMM UEM and click the Sync UEM icon.
- Enter the credentials and click Verify.
- Click Done.