SAML Users/Roles

SAML Users/Roles

SAML Users/Roles
SAML Users/Roles
3 weeks ago - last edited 2 weeks ago
Hardware Version:
Firmware Version: 5.15.20.17

 

I have recently installed the BETA copy of the software controller and I am mostly happy with it so far. We previously had numerous OC200 controllers - one per site.

 

Under "Accounts" I see there is provision for  SAML User and SAML Role. 

 

Am I correct to think that by using these functions I should be able to configure login to the controller to be needing an approved Microsoft EntraID account  ?

 

Would there be any documentation/guidance available for how to configure on the Omada Controller and within Entra ? 

 

 

Thanks,

 

 

Andy 

  0      
  0      
#1
Options
2 Accepted Solutions
Re:SAML Users/Roles-Solution
2 weeks ago - last edited 2 weeks ago

Hi  @tiny-pangolin 

 

You should be able to copy the entry ID from the following page:

 

Recommended Solution
  0  
  0  
#4
Options
Re:SAML Users/Roles-Solution
Saturday - last edited Saturday

Hi  @AndyBH    @ekrizon

 

Below is the configuration guide:

How to Configure SAML SSO on Omada Controller

Recommended Solution
  0  
  0  
#7
Options
11 Reply
Re:SAML Users/Roles
3 weeks ago - last edited 3 weeks ago

  @AndyBH 

 

Am I correct to think that by using these functions I should be able to configure login to the controller to be needing an approved Microsoft EntraID account  ?

>>> Yes. 

 

Currently, we don't have a guide about this config. Do you have any question when configuring it?

  0  
  0  
#2
Options
Re:SAML Users/Roles
2 weeks ago

  @Vincent-TP When Trying to configure this with authentik, I receive an error saying invalid parametrs when I load the data from a url or file. If I enter the data manually I get an error saying invalid format on the Entity ID. What format does the entity ID need? Also do you know when docs will be available for this?

  0  
  0  
#3
Options
Re:SAML Users/Roles-Solution
2 weeks ago - last edited 2 weeks ago

Hi  @tiny-pangolin 

 

You should be able to copy the entry ID from the following page:

 

Recommended Solution
  0  
  0  
#4
Options
Re:SAML Users/Roles
2 weeks ago

  @Vincent-TP 

 

Sorry Vincent, I would need guidance on both ends - the Controller and the Microsoft end.

 

By the look of it I would create a "custom app" under IntraID Enterprise Applications ?

 

 

I basically want to be able to use our Microsoft AD/Entra usernames and passwords to log into the omada controller (running on Windows Server on our domain).

 

 

Thanks, 

 

Andy 

  0  
  0  
#5
Options
Re:SAML Users/Roles
a week ago

This is now in Stable release as well 5.15.20.19.  I still can't find any official documentation on how to configure with the major IdPs (Entra, Google, Okta)...

 

I am very familiar with setting up SAML apps within our Entra tenant but so many questions regarding your implementation.

 

Specifically for on-prem hosted controllers:

 

How does enabling SAML interoperate if you have enabled cloud access and have cloud enabled users?

Does SAML redirect through your cloud services to reach our on-prem box?

Or is this local only and cloud users can still login separately with their TPLink IDs?

If thats the case then we will need to configure some kind of reverse proxy to make on-prem controller reachable from Entra ID correct?

Once enabled are local users still able to login alongside SAML users? Cloud users? 

If not, is there a fallback URL for local users if SAML is ever misconfigured/expired?

 

Thanks,

 

 

 

  0  
  0  
#6
Options
Re:SAML Users/Roles-Solution
Saturday - last edited Saturday

Hi  @AndyBH    @ekrizon

 

Below is the configuration guide:

How to Configure SAML SSO on Omada Controller

Recommended Solution
  0  
  0  
#7
Options
Re:SAML Users/Roles
Wednesday

  @Vincent-TP 

 

Hi Vincent,

 

Thanks for the documentation.

 

I have SAML via Entra ID now configured as per the instructions and technically it works and we can login, however we have one issue. After signing in with your M365 credentials it redirects you to our controllers IP address URL instead of our properly configured hostname which of course in browser you receive a connection not private screen.

 

Our Omada controller is on-premise and when you create a new SAML configuration within, it automatically assigns its Entity ID and Sign-On URL as IP address and does not seem to be editable.

 

We have a proper public SSL certificate on our controller and it is reachable via https://omada.mycompany.com.  I have the Entra ID Identifer and Reply URL defined as our  https://omada.mycompany.com hostname as well.  Just need to know how to change it on the Omada side so we can retain SSL and security all the way through.

  0  
  0  
#8
Options
Re:SAML Users/Roles
Wednesday
Never mind my above question, had to change from using IP to hostname in the regular systems settings. Separate question, is there a direct access URL for SAML users? Or do they need to go through the M365 app launcher.
  0  
  0  
#9
Options
Re:SAML Users/Roles
Yesterday

Hi  @ekrizon 

 

 is there a direct access URL for SAML users? Or do they need to go through the M365 app launcher.

>>> They need to go through the M365 APP.

  0  
  0  
#10
Options
Re:SAML Users/Roles
Yesterday

  @Vincent-TP 

Thanks Vincent.  That would be something nice to see in a future release, the ability to have SAML set as the default and only authentication method for the portal.  Then have a unique fallback URL that would still allow local login for if SAML is broken and you need to login to disable it.

 

It is quite awkward for our admins to not be able to go directly to omada.mycompany.com and be able to login.

  0  
  0  
#11
Options