---
title: "Prerequisites for Configuring Access Authentication"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35430215/Prerequisites%20for%20Configuring%20Access%20Authentication"
format: markdown
---
<span style="color: #000000">Consider the following before you configure and enable access authentication:</span>

- <span style="color: #000000">Enabling the access authentication service might affect the existing DNS service. Contact Infoblox Technical Support for assistance in enabling the access authentication service. Once the service is enabled, all users will be redirected to the </span>*<span style="color: #000000">Access Authentication</span>*<span style="color: #000000"> page for authentication before any DNS resolution can happen. Depending on what service is being synched, the administrator must have sufficient privileges to read Active Directory data. </span>
- <span style="color: #000000">The access authentication service is available on virtual hosts and Infoblox Platform Endpoint only. The service is not supported on NIOS and physical B1-105 appliances.</span>
- <span style="color: #000000">Using Mozilla FireFox with IPv6 might cause connection issues when configuring access authentication. To fix the problem, disable IPv6 in FireFox.</span>
- <span style="color: #000000">Smart Redirect does not work when </span>`infoblox.com`<span style="color: #000000"> is included in the Internal Domains List.</span>

<span style="color: #000000">Before you configure an authentication profile, ensure that you have successfully integrated an application with the selected third-party IdP using the protocol of your choice. The following are prerequisites for configuring access authentication: </span>

- <span style="color: #000000">You must successfully create an application for the authentication protocol in the respective third-party IdP that you plan to integrate with Infoblox Platform. For information about how to set up applications for different IdPs, refer to the respective vendor documentation.</span>
- <span style="color: #000000">Ensure that you have properly configured group and claim attributes for the respective application in the IdP. For SAML, the </span>**<span style="color: #000000">SAML2.0 Assertion</span>**<span style="color: #000000"> must contain the "</span>**<span style="color: #000000">groups</span>**<span style="color: #000000">" attribute. For OpenID Connect, the </span>**<span style="color: #000000">ID Token</span>**<span style="color: #000000"> must contain the "</span>**<span style="color: #000000">groups</span>**<span style="color: #000000">" claim. You can a</span>lso use an optional claim that matches the ".*email" regex, for displaying username in the security reports.
- <span style="color: #000000">Copy all the Service Provider details in the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog of the </span><span style="color: #202124">Infoblox</span><span style="color: #000000"> Portal. From the </span><span style="color: #202124">Infoblox</span><span style="color: #000000"> Portal, click </span>**<span style="color: #000000">Configure</span>**<span style="color: #000000"> > </span>**<span style="color: #000000">Administration</span>**<span style="color: #000000"> > </span>**<span style="color: #000000">Access Authentication </span>**<span style="color: #000000">> </span>**<span style="color: #000000">Add Configuration</span>**<span style="color: #000000">. Depending on the protocol you have chosen, copy the </span>**<span style="color: #000000">Entry ID</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Assertion Consumer Service URL</span>**<span style="color: #000000"> for SAML, and the </span>**<span style="color: #000000">Login Redirect URI</span>**<span style="color: #000000"> for OpenID Connect. You can also download the metadata file for SAML to get all the required information. You need this information to create an application in the IdP.</span>
- <span style="color: #000000">From the IdP application, obtain the identity provider details, so you can enter the information to successfully create an authentication profile in Infoblox Platform. For SAML, obtain the </span>**<span style="color: #000000">Issuer</span>**<span style="color: #000000">, </span>**<span style="color: #000000">SSO URL,</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Signing Certificate</span>**<span style="color: #000000"> from the SAML application of your IdP. You can also use the metadata URL to get all the information in the XML file. For OpenID Connect, obtain the </span>**<span style="color: #000000">Client ID</span>**<span style="color: #000000">, </span>**<span style="color: #000000">Client Secret</span>**<span style="color: #000000">, and </span>**<span style="color: #000000">Issuer</span>**<span style="color: #000000"> information from the OpenID Connect application.</span>

<span style="color: #000000">See the following for a list of required parameters for each supported third-party IdP and protocol:</span>

> Macro (children)