Skip to main content

 

Cisco Meraki Documentation

How to Configure SAML SSO With OneLogin

Overview 

OneLogin can act as an Identity Provider (IdP) for the Cisco Meraki Dashboard, enabling users to sign in through SAML single sign-on (SSO). This article provides an example walk-through of the configuration on both the OneLogin and Dashboard sides. 

Before proceeding, refer to the article on SAML integration for Dashboard

Prerequisites 

  • A OneLogin account with a user that has permissions to create company apps. 
  • Access to the Cisco Meraki Dashboard with permissions to configure Organization > Settings > SAML Configuration and Organization > Administrators > SAML administrator roles

Step-by-step instructions 

Add and configure the Meraki app in OneLogin 

  1. Sign in to OneLogin as a user with permissions to create company apps. 

  1. From the home page, select APPS > Add Apps

 Click APPS the Add Apps.png

  1. Search for meraki and select the Meraki app. 

Search Meraki app.png

  1. On the initial configuration page: 

  1. Under Personal or Organization App, choose the bubble for the organization.
    Personal or Organization App.png

  2. Under Connectors, choose the bubble for SAML2.0
    Connectors choose SAML2.0.png

  3. Select Save

Configure the SAML consumer URL and certificate 

  1. On the Configuration tab, enter the SAML Consumer URL. This is the Consumer URL from Organization > Settings > SAML Configuration in Dashboard. 

Configuration tab, enter the SAML Consumer URL.png

  1. On the SSO tab, select View Details under the X.509 Certificate

SSO tab click on View Details under the X.509 Certificate.png

  1. Copy the SHA1-Fingerprint and enter it in the X.509 cert SHA1 fingerprint field under Organization > Settings > SAML Configuration in Dashboard. 

Enter SHA1-Fingerprint.png

  1. Return to the previous page by selecting the Meraki (or custom name entered earlier) app under Apps using this certificate. Then select the SSO tab. 

(Optional) Enable Single Logout 

Enable Single Logout (SLO) by copying the SLO Endpoint (HTTP) field and pasting it into the SLO logout URL field under Organization > Settings > SAML Configuration in Dashboard. 

If enabled, logging out in Dashboard logs the user out of OneLogin and any compatible apps as well. 

Copy SLO Endpoint.png

Set access roles 

  1. On the Access tab, ensure that any desired Roles are selected. If none are selected, manually give users access to the app. 

  1. Select Save

Access tab choose desired roles.png

Grant user access and assign a role 

  1. On the Users tab, select a user to grant access. In this example, the user 'SAML Demo' is part of the 'Default' role. 

Users tab and grant access.png

  1. Enter a Role for the user. This must match a Role configured under Organization > Administrators > SAML administrator roles in Dashboard. 

Enter a Role for the user.png

  1. Select Save

Meraki app.png

Verification 

The configured user can seamlessly sign in to Dashboard by selecting the Meraki app. 

Troubleshooting 

If an error appears, confirm that all necessary fields are correctly populated and that both the user's Role and the SHA1 fingerprint match correctly between OneLogin and Dashboard. 

For information on resolving possible error messages, refer to the article on SAML Login History Error Messages.

Additional resources

  • Was this article helpful?