Single Sign-On
MetaDefender Software Supply Chain can authenticate users through your identity provider with OpenID Connect or SAML 2.0. Users sign in with their corporate account, and MetaDefender grants them the Administrator or Read-only role based on the group the identity provider sends.
Local accounts keep working after you enable SSO. The login page shows Sign In with SSO next to the local login form.
Before you start
HTTPS is required. Identity providers reject redirect URIs that use plain HTTP, except
http://localhost, and the MetaDefender session cookie is only sent over HTTPS. Enable HTTPS first. See Configuring HTTPS.Open MetaDefender at the address your users will use. MetaDefender takes the redirect URI from the browser address you are on when you save the SSO settings. Save from
https://mdssc.example.com, and the redirect URI becomeshttps://mdssc.example.com/callback.You need the Administrator role to change SSO settings. Administrators who signed in through SSO can view the page but cannot save it.
Decide the two groups. Create or choose two groups, or application roles, in your identity provider: one for administrators and one for read-only users. Group names are matched exactly and are case-sensitive.
Register MetaDefender with the identity provider
The steps below are for Microsoft Entra ID. Okta, Auth0, ADFS and PingFederate need the same four items: a redirect URI, a client ID and secret (OpenID Connect) or a signing certificate (SAML), and group or role claims in the token.
In the Entra admin center, create an App registration for MetaDefender.
Under Authentication, add a Web platform with the redirect URI
https://<your-mdssc-address>/callback. For SAML, usehttps://<your-mdssc-address>/callback/saml.Under Authentication, enable ID tokens in the implicit grant and hybrid flows section. MetaDefender requests
code id_token.Under Certificates & secrets, create a client secret. Copy the value now. Entra shows it only once.
Under App roles, create two roles. The role value is what MetaDefender matches, for example
MDSSC-AdminsandMDSSC-ReadOnly.In Enterprise applications, open the application and assign users or groups to the two roles.
Note the Application (client) ID and the Directory (tenant) ID. You need both in the next section.
Configure SSO in MetaDefender
Sign in as an Administrator and go to Settings > SSO Configuration.
Turn on Enable Single Sign-On.
Select the SSO Type: OpenID Connect or SAML 2.0.
Select the Identity Provider: Microsoft Entra ID, Okta, Auth0, ADFS or PingFederate.
Fill in the fields for your SSO type.
Under Role Mapping, enter the two group names.
Click Save.
The Save button stays disabled until you change a value.
Fields for OpenID Connect
Field | Value |
|---|---|
Authority URL | The issuer URL of your tenant. For Entra: |
Client ID | The Application (client) ID of the app registration |
Client Secret | The client secret value |
Fields for SAML 2.0
Field | Value |
|---|---|
Authority URL | The base URL of the identity provider, for example |
Identity Provider Issuer | The entity ID the identity provider puts in its assertions |
Identity Provider Login URL | The single sign-on service URL |
Identity Provider Logout URL | The single logout service URL |
Identity Provider Certificate | The identity provider's signing certificate, as a |
Role Mapping
Field | Value |
|---|---|
Administrator group | The group or application role whose members get the Administrator role |
Read-only group | The group or application role whose members get the Read-only role |
Enter the group name only, for example MDSSC-Admins. The two names must differ. If you leave a field empty, MetaDefender uses SsoAdministrator for administrators and SsoReadOnlyAdministrator for read-only users, so you can also name your identity provider groups that way and leave both fields empty.
Matching is case-sensitive. mdssc-admins does not match MDSSC-Admins.
For ADFS and PingFederate, the identity provider sends LDAP distinguished names such as CN=MDSSC-Admins,OU=Groups,DC=example,DC=com. Enter the group name only, MDSSC-Admins. MetaDefender finds it inside the distinguished name.
Secrets and certificates
MetaDefender stores the client secret and the SAML certificate encrypted and never shows them again. The fields show Stored when a value exists.
To save any change on this page, enter the Client Secret again. A save with an empty secret is rejected. For SAML, upload the certificate again when you change other fields.
How users sign in
The user clicks Sign In with SSO on the login page.
The browser goes to the identity provider. The user signs in there, including any multi-factor authentication.
The identity provider returns the user to MetaDefender. MetaDefender creates the user account on first sign-in and grants the role mapped from the user's group.
The role is resolved at every sign-in. When you move a user to the other group in the identity provider, the change applies the next time the user signs in.
If the identity provider does not send a group that matches one of the two entries, the sign-in fails and MetaDefender does not create the account. Add the user to one of the two groups in the identity provider and sign in again.
Users created through SSO appear on the Users page like local users. See User management.
Troubleshooting
Symptom | Cause | Fix |
|---|---|---|
Sign In with SSO is not on the login page | SSO is disabled | Turn on Enable Single Sign-On and save |
Entra shows error AADSTS50011, redirect URI mismatch | The redirect URI registered in Entra differs from | Register the exact URI, or open MetaDefender at the registered address and save the SSO settings again |
After signing in at the identity provider, MetaDefender shows Tenant Configuration service error | The sign-in took longer than 15 minutes, for example during multi-factor registration, or the browser blocked the sign-in cookies | Start the sign-in again. Complete multi-factor registration before signing in to MetaDefender |
The user signs in but every action says the role does not allow it | The user's group matched the Read-only group | Move the user to the administrator group in the identity provider and sign in again |
The user signs in at the identity provider, but MetaDefender rejects the sign-in and no account appears on the Users page | The user is in neither group, or the group name differs in case from the Role Mapping entry | Compare the group name in the identity provider with the Role Mapping fields, character by character. Add the user to the group and sign in again |
Save fails with Use a different group for each role | Both Role Mapping fields hold the same name | Enter two different group names |
Save fails with Enter a valid http or https URL | The Authority URL or an identity provider URL is malformed | Enter the full URL including the scheme |