Define Duo to authenticate Cortex XSOAR
Define Duo to authenticate Cortex XSOAR 6.13.
Before you start, create a Duo group for Cortex XSOAR users.
Log in to Duo and click Applications.
Click Protect an Application.
Find Generic Service Provider - 2FA with SSO hosted by Duo (Single Sign-On) in the application list and click Protect.

duo-generic-service-provider.png In the Service Provider section, enter the following, using the url of your Cortex XSOAR installation:
ParameterValueEntity ID
https://
<cortexxsoarURL>Assertion Consumer Service
https://
<cortexxsoarURL>/samlSingle Logout URL
https://
<cortexxsoarURL>/saml-logoutService Provider Login URL
Keep this field blank.
Default Relay State
Keep this field blank.
In the SAML Response section, change the following:
Change the NameID format drop-down from
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddresstourn:oasis:names:tc:SAML:1.1:nameid-format:unspecified.
duo-nameid-format.png Leave NameID attribute as
<Email Address>and Signature algorithm asSHA256.In the Signing Options section, clear the
Sign assertioncheckbox.
duo-signing-option.png
Map attributes:
IdP AttributeSAML Response Attribute<Username>
urn
<Email Address>
Email
<First Name>
FirstName
<Last Name>
LastName
Role attributes:
ParameterValueAttribute name
memberOf
Service Provider’s Role
The SAML role in Cortex XSOAR that will be mapped to the Duo group
Duo Groups
The Duo group you created
Click Save.
Last updated
Was this helpful?
