Comment on page
How to configure Keeper SSO Connect Cloud with DUO SSO for seamless and secure SAML 2.0 authentication.
These instructions assume Duo has already been successfully enabled and configured with an authentication source (Active Directory or IdP). To activate Duo SSO, visit your Duo Admin Panel and visit the "Single Sign-On" section.
Log in to the Duo Admin Panel and click Protect an Application. Locate the entry for Generic Service Provider with a protection type of "2FA with SSO hosted by Duo (Single Sign-On)" in the applications list then click "Protect".
Protect Generic Service Provider
Set up Generic SAML Service Provider - Single Sign On
The Download section is where you can download the SAML metadata file to upload into your SSO provisioning method.
Download DUO Metadata file
Back on the Keeper Admin console, locate your DUO SSO Connect Cloud Provisioning method and select Edit.
Edit DUO SSO Provisioning Method
Scroll down to the Identity Provider section, set IDP Type to GENERIC, select Browse Files and select the DUO Metadata file previously downloaded.
Still within the Keeper Admin Console, exit Edit View and select View on your DUO SSO Connect Cloud Provisioning method. Within the Service Provider section you will find the metadata values for the Entity ID, IDP Initiated Login Endpoint and Assertion Consumer Service (ACS) Endpoint.
Single Logout Service (SLO) Endpoint is optional.
View DUO SSO Provisioning Method
Return to the application page in your Duo Admin Panel, copy and Paste the Entity ID, Login Endpoint and ACS Endpoint into the Service Provider section.
Keeper Metadata Info
Within the SAML Response section, scroll down to Map attributes and map the following attributes.
Ensure that 3 attributes ("First", "Last" and "Email") are configured with the exact spelling as seen below.
Within the Policy section, defines when and how users will authenticate when accessing this application. Your global policy always applies, but you can override its rules with custom policies.
User or Group Policy
Within the Global Policy section, Review / Edit / Verify any Global Policy as seen by your DUO and or Keeper administrator.
Within the Settings section, Name the application Keeper Security EPM - Single Sign-On. All other settings are set as seen by your DUO and or Keeper administrator.
Keeper Security EPM - Single Sign-On
At the very bottom of the page, click on Save to save the protected application settings.
Success! Your Keeper Security EPM - Single Sign-On setup is now complete!
If you need assistance implementing the Keeper Security EPM - Single Sign-On application within your DUO environment, please contact the Keeper support team.
Users created in the root node (top level) in the Keeper Admin Console will need to be moved to the SSO node if you want the users to login with Duo. An admin cannot move themselves to the SSO enabled node, another admin must perform this action.
After the user is moved to the SSO enabled node, they can login to the Keeper vault by simply typing their email address and clicking "Next". If this does not work, please ensure that your email domain (e.g. company.com) has been reserved to your enterprise and ensure that Just-In-Time provisioning is enabled.
To onboard with the Enterprise Domain, the user can select the "Enterprise SSO" pull down and type in the Enterprise Domain configured in the Keeper Admin Console.
Initially select 'Enterprise SSO Login'
Once the user has authenticated with SSO, they only need to use their email address moving forward to initiate SSO authentication.
If typing in the email address and clicking Next does not route the user to the desired SSO, ensure that just-in-time provisioning is enabled in the Keeper SSO configuration and ensure that your email domain is reserved by Keeper. More information regarding routing and domain reservation can be found here.