Setting Up OneLogin
- Log in to the OneLogin administration console.
- In the top navigation bar, click APPS > Add Apps.
- In the Find Applications search bar, enter
OneLogin SAML Test (IdP) w/ NameID (unspecified)
and click the resulting entry to create a new app: - On the Info tab, enter a name and optionally upload an icon.
- Click the Configuration tab and enter the SAML Consumer URL.This is the Lookout ACS URL for your tenant, provided by Lookout:
- Click the Parameters tab, then under Credentials are select Configured by admin.
- Add the following attributes by clicking Add parameter. For parameters with static values, select -Macro- as the value type and enter the desired value:
OneLogin SAML … Field Value Description NameID (SAML Subject) Email The default ID field. ent - Macro - This is your Lookout enterprise tenant GUID, for example: " 78902dc0-b8ab-4abc-12c7-4a2b980ec23a
"givenname First Name The user's first name. mail Email The user's email. memberOf - Macro - This should be a
"Contains"
match against a common String in the user group names you use for Lookout MES Console Full Access, Restricted Access, Read-Only , and Enrollment Only administrators. For example, if your user groups are named:- Lookout-Full
- Lookout-Restricted
- Lookout-ReadOnly
- Lookout-EnrollmentOnly
Then the
memberOf
- Macro - Value should be:"Contains" = "Lookout"
sn Last Name The user's last name. upn Email The user's principal name. - Click MORE ACTIONS > SAML Metadata to download the SP metadata for Lookout: