---
title: "Configuring IdP Authentication"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35398160/Configuring%20IdP%20Authentication"
format: markdown
---
<span style="color: #000000">Before configuring IdP settings, you first configure 3rd party IdP authentication by associating an IdP protocol with a domain. The SSO Portal supports using a single IdP configuration on multiple domains. You can use the same IdP configuration to authenticate users from multiple domains, as long as the domains match the federated configuration. To configure multiple-domain authentication, you first add a primary domain and prove mastery of it, and then add other domains and link them to the primary domain and its IdP configuration. For information about adding domains, see </span><span style="color: #000000">*[Configuring Domains](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35397045)*</span><span style="color: #000000">.</span>

> ⚠️ ### Note
> ⚠️ 
> ⚠️ <span style="color: #000000">To link multiple domains to the primary domain, ensure that you complete the following:</span>
> ⚠️ 
> ⚠️ - <span style="color: #000000">Complete the IdP configuration for the primary domain and keep it active.</span>
> ⚠️ - <span style="color: #000000">Prove mastery of all domains you want to link to the primary domain.</span>
> ⚠️ - <span style="color: #000000">For domain linking to function properly, the linked domain must not have an active IdP configuration associated with it before linking to another IdP configuration. If the domain has an IdP configuration associated with it, ensure that you remove the configuration before linking the domain.</span>

# <span style="color: #000000">Single-domain IdP Authentication</span>

<span style="color: #000000">To configure IdP authentication for a single domain, complete the following:</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal at </span><span style="color: #000000">[https://sso.infoblox.com/](https://sso.infoblox.com/)</span><span style="color: #000000">.</span>
2. <span style="color: #000000">Navigate to the </span><span style="color: #000000">*3rd Party IDP*</span><span style="color: #000000"> tab (</span><span style="color: #000000">**Configure**</span><span style="color: #000000">> </span><span style="color: #000000">**Authentication**</span><span style="color: #000000"> > </span><span style="color: #000000">**3rd Party IDP**</span><span style="color: #000000">).</span>
3. <span style="color: #000000">On the </span><span style="color: #000000">*3rd Party IDP*</span><span style="color: #000000"> tab, click </span><span style="color: #000000">**Select Domain**</span><span style="color: #000000"> on the right upper navigation bar.</span>
4. <span style="color: #000000">From the </span><span style="color: #000000">**Select Domain**</span><span style="color: #000000"> drop-down menu, select a domain on which you want to configure 3rd party IdP.</span>


5. <span style="color: #000000">Once the domain is selected, you must select the protocol you want to utilize in establishing the connectivity between your IdP and SSO Portal.</span>
  From the **Select IDP Protocol** menu, select one of the following:
  - **SAML 2.0** for Okta and ForgeRock
  - **Azure SAML** for Azure AD (Active Directory)
6. The SSO Portal displays the selected domain and protocol, as shown below:
  
7. After you have selected a domain and a protocol, you can complete the following 3rd party IdP settings:

- <span style="color: #000000">*[Generating Audience Keys](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367311)*</span>
- <span style="color: #000000">*[Configuring SAML 2.0 Application for OKTA](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35366534)*</span>
- <span style="color: #000000">*[Configuring SAML 2.0 Application for Microsoft Entra ID](https://docs.infoblox.com/space/BloxOneCloud/35366790/Configuring+SAML+2.0+Application+for+Microsoft+Entra+ID)*</span>
- <span style="color: #000000">*[Configuring SAML 2.0 Application for ForgeRock](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35430556)*</span>
- <span style="color: #000000">*[Mapping User Groups](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463665)*</span>

# <span style="color: #000000">Multiple-domain IdP Authentication</span>

<span style="color: #000000">Before you configure multiple-domain IdP authentication, consider the following:</span>

- <span style="color: #000000">The primary domain configuration, including group mappings, applies to all linked domains. The configuration for linked domains is a read-only copy of the primary domain configuration. To edit the IdP configuration, you must select the primary domain from the </span><span style="color: #000000">**Select IDP Protocol**</span><span style="color: #000000"> drop-down menu. </span>
- <span style="color: #000000">Deactivating or resetting the primary domain will unlink all domains, resulting in the need to re-link them after reactivation.</span>
- <span style="color: #000000">For domain linking to function properly, the linked domain must not have an active IdP configuration associated with it before linking to another IdP configuration. If the domain has an IdP configuration associated with it, ensure that you remove the configuration before linking the domain.</span>

<span style="color: #000000">To configure IdP authentication for multiple domains, complete the following:</span>

1. Log in to the Infoblox SSO Portal at [https://sso.infoblox.com/](https://sso.infoblox.com/).
2. On the *3rd Party IDP* tab, click **Select Domain** on the right upper navigation bar.
3. From the **Select Domain** drop-down menu, select the domain you want to link to the primary domain.
4. From the *Select IDP Protocol* menu, select **Link to <*****primary domain*****> <*****IdP Protocol*****>**, where *primary domain* is the domain name of the primary domain and *IdP protocol* is the federated IdP configuration of the primary domain.   
In the following example, you would select **Link to Test.com SAML 2.0** from the drop-down menu to link `Example.domain.com` to [Test.com](http://Test.com) using the SAML 2.0 IdP configuration.
5. In the warning dialog, click **Confirm** to confirm that you want to link the domain to the primary domain.
6. To the right of the domain name, the Infoblox Portal displays the federation status and the primary domain to which this domain is linked, as follows:
7. Repeat the above steps if you want to link multiple domains to the primary domain. Note that all linked domains share the same IdP configuration of the primary domain.

# Unlinking a Domain from Multiple-Domain IdP

To unlink a domain from the primary domain, complete the following:

1. Log in to the Infoblox SSO Portal at [https://sso.infoblox.com/](https://sso.infoblox.com/).
2. On the *3rd Party IDP* page, click **Select IDP Protocol** on the right upper navigation bar.
3. From the **Activate** drop-down menu, select **Unlink from <*****primary domain*****>**, as shown in the following: