Lookout Product Documentation

Find answers about using and optimizing Lookout products.

Configure Identity Provider

Creating a SAML-based application in Azure gives Azure the information it needs to communicate with the Lookout Cloud Security Platform, enabling the platform to enforce policies based on user credentials.

  1. Sign in to the Microsoft Entra admin center with an account that has Cloud Application Administrator permissions.
  2. Select Identity > Applications > Enterprise applications > New application.
  3. In the Add from the Gallery section, search for and select Lookout Secure Access.
  4. Add the app.
    You may need to wait a few moments for the app to be added to your tenant.
  5. Select Identity > Applications > Enterprise applications > Lookout Secure Access > Single sign-on.
  6. On the Select a single sign-on method page, select SAML.
  7. On the Set up single sign-on with SAML page, click the pencil icon to edit the Basic SAML Configuration.
  8. Click Upload metadata file and browse to the location where you saved the downloaded SP metadata file.
  9. Click Upload.
  10. Verify that Azure has populated the Identifier and Reply URL fields in the Basic SAML Configuration section.
  11. On the Attributes & Claims page, locate Unique User Identifier (Name ID) and click the three dots to edit this entry.
  12. Set the Name identifier format to Unspecified and click Save.
  13. On the Set up single sign-on with SAML page, in the SAML Signing Certificate section, copy the App Federation Metadata URL.
  14. On the Overview page for your Lookout Secure Access app, click Assign users and groups.
  15. Add the necessary users and groups.