SlideShare a Scribd company logo
External Identity
• Setting up external identity means that you configure an identity
provider (IdP) to authenticate an acting agent (either an user, a client,
or both) and then assert to Anypoint Platform that said agent has
been validated by it and should be trusted.
• This means that you can set up:
• External identities for user management using SAML 2.0
• External identities for client management using OAuth 2.0
• External identities for both user and client management
User Management
• The Anypoint Platform can be integrated with your organization’s
external federated identity system allowing your users to have single
sign-on (SSO) access to your Anypoint Platform organization.
• In order to configure it, use the SAML configuration instructions in the
section below and consult your IdPs specific documentation for
instructions on how to apply this configuration for your intended
provider.
Identity Providers
• The Anypoint Platform supports SAML 2.0 compliant identity management providers for user management and SSO.
• Although any SAML 2.0 compliant provider can be configured for this use, the following IdPs have been successfully tested as working with Anypoint Platform:
• Ping Federate
• OpenAM
• Okta
• Shibboleth
• ADFS
• onelogin
• CA SiteMinder
• For these providers, the 'Assertion Consumer Service' or 'SAML Assertion URL' is https://anypoint.mulesoft.com/accounts/login/receive-id and the 'entityID' or 'Audience URL' is any string value that identifies your
organization. By convention it is <organizationDomain>.anypoint.mulesoft.com, but any value is acceptable.
Instructions for SAML Configuration
• The instructions in this document allow you to configure your Anypoint Platform organization with any of the
supported SAML 2.0 providers for SSO.
• To configure federated identity:
• Configure your SAML provider to set up your Anypoint Platform organization as your audience.
• Set the Assertion Consumer Service to send an HTTP POST request to the following address:
https://anypoint.mulesoft.com/accounts/login/receive-id
• Log in with an administrator account into your Anypoint organization, click on the gear icon in the Nav bar
which will take you to the Access Manager user interface , and select External Identity. If you haven’t set
anything yet, you should see a screen like this
• Click the link for "If you would like to configure single sign on with a SAML 2.0 provider you can get
started here" and then provide the necessary data in the SAML 2.0 form to set up your Anypoint
organization for SSO
Federated Organizations - Map Users to Anypoint
Platform Roles
• As of November 2014, Anypoint Platform provides a feature to help you map users in a federated organization’s LDAP group to an Anypoint Role.
• This requires that your Anypoint Platform organization utilizes an external identity provider such as PingFederate.
• This feature enables users in an organization to sign in to Anypoint Platform using the same organizational credentials and access permissions that an
organization maintains using LDAP.
• This ensures credential security and maintains organizational roles for accessing privileged information.
• To support this feature you first need to configure an external identity following any of the methods described above, and then follow the two steps
described below:
• Verify SAML Information
• The SAML assertion is an XML file that is issued by the external identity provider.
• Log into Anypoint Platform and click the External Identity tab to verify your organization’s Identity management information.
Client Management
• Client Management allows any client connecting to your application
to identify itself using OAuth 2.0.
• An OAuth client application interacts with the provider´s
authorization server to obtain access tokens needed to call OAuth-
protected services at the Anypoint Platform´s resource server.
• The only OAuth 2.0 supported IdPs that work with Anypoint Platform
are openAM and Ping Federate
openAM
• If you want to use openAM for client management and if you’re not
using Anypoint Platform on premises, you need to request that your
account be configured in that way, as you can’t set this up manually.
• Work with your MuleSoft account representative to ensure that we
are aware of your needs for configuring your organization with
PingFederate.
• Complete the OpenAM form and MuleSoft will get back to you within
48 hours with either the completion of the configuration or follow-up
questions to complete the configuration.
Ping Federate
• If you want to use Ping Federate for client management and if you’re not
using Anypoint Platform on premises, you need to request that your
account be configured in that way, as you can’t set this up manually.
• Work with your MuleSoft account representative to ensure that we are
aware of your needs for configuring your organization with PingFederate.
• Complete the Ping Federate Form. After you complete this form, MuleSoft
gets back to you within 48 hours with either the completion of the
configuration or follow-up questions to complete the configuration.
Single Log Out
• Single log out is important so that a user or user agent can log out of an
authenticated environment and ensure that both service providers and identity
servers process the log out correctly.
• To configure single log out:
• In PingFederate, click the SP Configuration for the Anypoint Platform.
• Go to Browser SSO and click Configure Browser SSO.
• Under SAML Profiles, ensure that these are set:
• IdP-Initiated SSO
• IdP-Initiated SLO
• SP-Initiated SLO
• Go to Protocol Settings and click Configure Protocol Settings.
• Configure a SLO Service Url with the following:
• Under Allowable SAML Bindings, click Redirect.
• Under Encryption Policy, make certain that nothing is encrypted.
• Save and click Done out of Protocol Settings and Browser SSO.
• When viewing the SP Configuration for Anypoint Platform, go to Credentials, and
click Configure Credentials.
• Under Signature Verification Settings, click Manage Signature Verification
Settings. Set the Trust Model to Unanchored, and import the attached certificate.
Make it the active certificate.

More Related Content

PPTX
Analytics event api
PPTX
Anypoint runtime manager v1
PPTX
Managing permissions
PPTX
Deploying to cloud hub
PPTX
Mq user and role access
PPTX
View api analytics
PPTX
Mule roles
PPTX
Anypoint access management
Analytics event api
Anypoint runtime manager v1
Managing permissions
Deploying to cloud hub
Mq user and role access
View api analytics
Mule roles
Anypoint access management

What's hot (19)

PPTX
Mule organization
PPTX
Creating a mule project with raml and api
PPTX
Mule esb stripe
PPTX
Mule access management - Managing Environments and Permissions
PPT
Mule cloudhubconsoleoverview-sathyaraj
PPTX
Manage and consume the api
PPTX
Mule users
PPTX
Integration with Microsoft SharePoint using Mule ESB
PPT
Mule cloud hub console overview
PPTX
Running mule as worker role on azure
PPTX
Mule management console installation
PPTX
Query in share point by mule
PPTX
Configuring Anypoint Studio MQ connector
PPTX
Github plugin setup in anypointstudio
PPTX
Introduce anypoint studio
PPTX
Troubleshooting anypoint platform
PPTX
Feature guide opportunity manager(awom)
PPTX
Mule tcat server - deploying applications
PPT
Mule cloud hub console overview
Mule organization
Creating a mule project with raml and api
Mule esb stripe
Mule access management - Managing Environments and Permissions
Mule cloudhubconsoleoverview-sathyaraj
Manage and consume the api
Mule users
Integration with Microsoft SharePoint using Mule ESB
Mule cloud hub console overview
Running mule as worker role on azure
Mule management console installation
Query in share point by mule
Configuring Anypoint Studio MQ connector
Github plugin setup in anypointstudio
Introduce anypoint studio
Troubleshooting anypoint platform
Feature guide opportunity manager(awom)
Mule tcat server - deploying applications
Mule cloud hub console overview
Ad

Viewers also liked (20)

PPTX
Anypoint mq acknowledgement mode
PPTX
Message structure
PDF
White Paper: Internal vs. External Identity Access Management
PDF
Pagination Done the Right Way
PDF
White Paper: Saml as an SSO Standard for Customer Identity Management
PDF
2015-11-24-me bios-digitale-fabriek-naar-kennisfabriek
PDF
elective_marketing_aCipolla_3EMBAPT
PDF
Drama Cempaka Berdarah
PPTX
Prosedur poligami
PPTX
1-APELL Introduction- Gablehouse
PPTX
Gas mulia
PPT
PPTX
презентация
PDF
Salesforce DUG meetup #10 MiniHack完全制覇の旅
PPTX
Ppt ta deal
PPT
Model discovery learning
PPT
Новогодний шар из текстиля
PPTX
My weekend at prssa 2014 national assembly
PPTX
Company Profile- CFMS.-1
Anypoint mq acknowledgement mode
Message structure
White Paper: Internal vs. External Identity Access Management
Pagination Done the Right Way
White Paper: Saml as an SSO Standard for Customer Identity Management
2015-11-24-me bios-digitale-fabriek-naar-kennisfabriek
elective_marketing_aCipolla_3EMBAPT
Drama Cempaka Berdarah
Prosedur poligami
1-APELL Introduction- Gablehouse
Gas mulia
презентация
Salesforce DUG meetup #10 MiniHack完全制覇の旅
Ppt ta deal
Model discovery learning
Новогодний шар из текстиля
My weekend at prssa 2014 national assembly
Company Profile- CFMS.-1
Ad

Similar to External identity (20)

PPTX
rich media with buttons LLM Commerce Framework.pptx
PPTX
Mulesoft Salesforce Connector - OAuth 2.0 JWT Bearer
PPTX
WordPress + Office 365 | Quick Installation Guide v9.6
PPTX
SuiteCRM Customer Portal
PDF
Microsoft mobile services
PPTX
OpenID Connect and Single Sign-On for Beginners
PDF
Saml sap netweaver_fiori
PDF
Lecture 11. Microsoft mobile services
PDF
Social Sign-On with Authentication Providers
PDF
Social Sign-On with Authentication Providers Webinar
PPTX
Licensing
PPTX
Secure Development on the Salesforce Platform - Part 3
PDF
How Identity Brokering Simplifies Access Management
PPTX
Salesforce Identity Management
PPTX
Integrating Okta with Anypoint Platform for a mobile security use case
PDF
Website Livechat Leads
PPTX
Marketing Cloud integration with MuleSoft
PPTX
Different architecture topology for dynamics 365 retail
PPTX
(Salesforce) Lightning Login - Dreamforce 2017
PPTX
Dyn crm2013 whatsnew_v1_0_cr
rich media with buttons LLM Commerce Framework.pptx
Mulesoft Salesforce Connector - OAuth 2.0 JWT Bearer
WordPress + Office 365 | Quick Installation Guide v9.6
SuiteCRM Customer Portal
Microsoft mobile services
OpenID Connect and Single Sign-On for Beginners
Saml sap netweaver_fiori
Lecture 11. Microsoft mobile services
Social Sign-On with Authentication Providers
Social Sign-On with Authentication Providers Webinar
Licensing
Secure Development on the Salesforce Platform - Part 3
How Identity Brokering Simplifies Access Management
Salesforce Identity Management
Integrating Okta with Anypoint Platform for a mobile security use case
Website Livechat Leads
Marketing Cloud integration with MuleSoft
Different architecture topology for dynamics 365 retail
(Salesforce) Lightning Login - Dreamforce 2017
Dyn crm2013 whatsnew_v1_0_cr

More from Son Nguyen (20)

PPTX
Your new maven friend – the mule maven
PPTX
Soa governance for the modern business
PPTX
Quality sdk for your apis in minutes!
PPTX
Maven tools & archetypes
PPTX
Let api change your relationship with your doctor
PPTX
Increase revenue and reinvigorate your business with api
PPTX
How to – wrap soap web service around a database
PPTX
How to – rest api proxy to soap webservice
PPTX
A good api strategy can help turn your
PPTX
10 steps to design and build the perfect
PPTX
What is the difference between using private flow
PPTX
Troubleshooting mule
PPTX
Real time data processing with anypoint connector for kafka
PPTX
Performance tuning in mule
PPTX
Mule intelli j tips
PPTX
Introducing the anypoint connector for redis
PPTX
How to – data integrity checks in batch processing
PPTX
How soa paved the way for cloud
PPTX
Anypoint mq queues and exchanges
PPTX
Cloud hub and mule
Your new maven friend – the mule maven
Soa governance for the modern business
Quality sdk for your apis in minutes!
Maven tools & archetypes
Let api change your relationship with your doctor
Increase revenue and reinvigorate your business with api
How to – wrap soap web service around a database
How to – rest api proxy to soap webservice
A good api strategy can help turn your
10 steps to design and build the perfect
What is the difference between using private flow
Troubleshooting mule
Real time data processing with anypoint connector for kafka
Performance tuning in mule
Mule intelli j tips
Introducing the anypoint connector for redis
How to – data integrity checks in batch processing
How soa paved the way for cloud
Anypoint mq queues and exchanges
Cloud hub and mule

Recently uploaded (20)

PPTX
Cloud computing and distributed systems.
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Machine learning based COVID-19 study performance prediction
PPTX
A Presentation on Artificial Intelligence
PDF
Reach Out and Touch Someone: Haptics and Empathic Computing
PPTX
Big Data Technologies - Introduction.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PPT
Teaching material agriculture food technology
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Modernizing your data center with Dell and AMD
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Cloud computing and distributed systems.
Spectral efficient network and resource selection model in 5G networks
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Machine learning based COVID-19 study performance prediction
A Presentation on Artificial Intelligence
Reach Out and Touch Someone: Haptics and Empathic Computing
Big Data Technologies - Introduction.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
“AI and Expert System Decision Support & Business Intelligence Systems”
The AUB Centre for AI in Media Proposal.docx
Dropbox Q2 2025 Financial Results & Investor Presentation
Teaching material agriculture food technology
Encapsulation_ Review paper, used for researhc scholars
The Rise and Fall of 3GPP – Time for a Sabbatical?
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Modernizing your data center with Dell and AMD
Agricultural_Statistics_at_a_Glance_2022_0.pdf
NewMind AI Monthly Chronicles - July 2025
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication

External identity

  • 2. • Setting up external identity means that you configure an identity provider (IdP) to authenticate an acting agent (either an user, a client, or both) and then assert to Anypoint Platform that said agent has been validated by it and should be trusted.
  • 3. • This means that you can set up: • External identities for user management using SAML 2.0 • External identities for client management using OAuth 2.0 • External identities for both user and client management
  • 4. User Management • The Anypoint Platform can be integrated with your organization’s external federated identity system allowing your users to have single sign-on (SSO) access to your Anypoint Platform organization. • In order to configure it, use the SAML configuration instructions in the section below and consult your IdPs specific documentation for instructions on how to apply this configuration for your intended provider.
  • 5. Identity Providers • The Anypoint Platform supports SAML 2.0 compliant identity management providers for user management and SSO. • Although any SAML 2.0 compliant provider can be configured for this use, the following IdPs have been successfully tested as working with Anypoint Platform: • Ping Federate • OpenAM • Okta • Shibboleth • ADFS • onelogin • CA SiteMinder • For these providers, the 'Assertion Consumer Service' or 'SAML Assertion URL' is https://anypoint.mulesoft.com/accounts/login/receive-id and the 'entityID' or 'Audience URL' is any string value that identifies your organization. By convention it is <organizationDomain>.anypoint.mulesoft.com, but any value is acceptable.
  • 6. Instructions for SAML Configuration • The instructions in this document allow you to configure your Anypoint Platform organization with any of the supported SAML 2.0 providers for SSO. • To configure federated identity: • Configure your SAML provider to set up your Anypoint Platform organization as your audience. • Set the Assertion Consumer Service to send an HTTP POST request to the following address: https://anypoint.mulesoft.com/accounts/login/receive-id • Log in with an administrator account into your Anypoint organization, click on the gear icon in the Nav bar which will take you to the Access Manager user interface , and select External Identity. If you haven’t set anything yet, you should see a screen like this • Click the link for "If you would like to configure single sign on with a SAML 2.0 provider you can get started here" and then provide the necessary data in the SAML 2.0 form to set up your Anypoint organization for SSO
  • 7. Federated Organizations - Map Users to Anypoint Platform Roles • As of November 2014, Anypoint Platform provides a feature to help you map users in a federated organization’s LDAP group to an Anypoint Role. • This requires that your Anypoint Platform organization utilizes an external identity provider such as PingFederate. • This feature enables users in an organization to sign in to Anypoint Platform using the same organizational credentials and access permissions that an organization maintains using LDAP. • This ensures credential security and maintains organizational roles for accessing privileged information. • To support this feature you first need to configure an external identity following any of the methods described above, and then follow the two steps described below: • Verify SAML Information • The SAML assertion is an XML file that is issued by the external identity provider. • Log into Anypoint Platform and click the External Identity tab to verify your organization’s Identity management information.
  • 8. Client Management • Client Management allows any client connecting to your application to identify itself using OAuth 2.0. • An OAuth client application interacts with the provider´s authorization server to obtain access tokens needed to call OAuth- protected services at the Anypoint Platform´s resource server. • The only OAuth 2.0 supported IdPs that work with Anypoint Platform are openAM and Ping Federate
  • 9. openAM • If you want to use openAM for client management and if you’re not using Anypoint Platform on premises, you need to request that your account be configured in that way, as you can’t set this up manually. • Work with your MuleSoft account representative to ensure that we are aware of your needs for configuring your organization with PingFederate. • Complete the OpenAM form and MuleSoft will get back to you within 48 hours with either the completion of the configuration or follow-up questions to complete the configuration.
  • 10. Ping Federate • If you want to use Ping Federate for client management and if you’re not using Anypoint Platform on premises, you need to request that your account be configured in that way, as you can’t set this up manually. • Work with your MuleSoft account representative to ensure that we are aware of your needs for configuring your organization with PingFederate. • Complete the Ping Federate Form. After you complete this form, MuleSoft gets back to you within 48 hours with either the completion of the configuration or follow-up questions to complete the configuration.
  • 11. Single Log Out • Single log out is important so that a user or user agent can log out of an authenticated environment and ensure that both service providers and identity servers process the log out correctly. • To configure single log out: • In PingFederate, click the SP Configuration for the Anypoint Platform. • Go to Browser SSO and click Configure Browser SSO. • Under SAML Profiles, ensure that these are set: • IdP-Initiated SSO • IdP-Initiated SLO • SP-Initiated SLO • Go to Protocol Settings and click Configure Protocol Settings. • Configure a SLO Service Url with the following:
  • 12. • Under Allowable SAML Bindings, click Redirect. • Under Encryption Policy, make certain that nothing is encrypted. • Save and click Done out of Protocol Settings and Browser SSO. • When viewing the SP Configuration for Anypoint Platform, go to Credentials, and click Configure Credentials. • Under Signature Verification Settings, click Manage Signature Verification Settings. Set the Trust Model to Unanchored, and import the attached certificate. Make it the active certificate.