
Create a Web logon procedure
- Login to the DualShield Administration Console
- In the main menu, select “Authentication > Logon Procedures”
- Click the “+ CREATE” button on the toolbar, on the right
- Enter a recognisable “Name” and select “Web SSO” as the Type
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_13-43-18.png](/download/attachments/35947795/image-2024-11-13_13-43-18.png?version=1&modificationDate=1731505397553&api=v2)
- Click “SAVE”
- Click the Context Menu icon of the newly created Logon Procedure, select “Logon Steps”
- In the popup window, click the “+ ADD” button on the toolbar
- Add the necessary Authentication methods here
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_13-45-31.png](/download/attachments/35947795/image-2024-11-13_13-45-31.png?version=1&modificationDate=1731505530448&api=v2)
Create a Web application
- In the main menu, select “Authentication > Applications”
- Click the “+ CREATE” button on the toolbar
- Enter a recognisable “Name”
- Select your internal “Realm”
- Add the newly created Logon Procedure (from the previous step)
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_13-54-52.png](/download/attachments/35947795/image-2024-11-13_13-54-52.png?version=1&modificationDate=1731506091790&api=v2)
- Click "Save"
- Click the context "..." menu of the newly created Application, then select "Agent"
- Select the "Single Sign-on Server (SSO Server)"
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_13-58-20.png](/download/attachments/35947795/image-2024-11-13_13-58-20.png?version=1&modificationDate=1731506299989&api=v2)
- Click "Save"
- Click the context "..." menu of the newly created Application, then select "Self Test"
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_14-0-19.png](/download/attachments/35947795/image-2024-11-13_14-0-19.png?version=1&modificationDate=1731506418657&api=v2)
Download the DualShield IdP Metadata
- In the main menu, navigate to " SSO > SSO Servers"
- Click the context "..." menu of "Single Sign-on Server (SSO Server") then select "Download Idp MetaData" .
Note the Name and location of the XML file, saved locally.
![DualShield MFA Platform > DualShield Configuration [Splunk] > image-2024-11-13_14-7-50.png](/download/attachments/35947795/image-2024-11-13_14-7-50.png?version=1&modificationDate=1731506869571&api=v2)
In order to create a Service Provider for Splunk within DualShield - Next complete the "Splunk SAML Configuration"
Plus Download the Splunk Service Provider (SP) Metadata.
Create a Service Provider
- In the main menu, select " SSO | Service Providers"
- Click "Create"
- Enter "Name", Select Type as "SAML 2.0"
- Copy the content of Service Provider Metadata (SPMetadata.xml) into the "Metadata" field.
![DualShield MFA Platform > DualShield Configuration [Splunk] > SplunkSP.png](/download/attachments/35947795/SplunkSP.png?version=1&modificationDate=1587386357000&api=v2)
- Click Edit for Attribute and create a role attribute map to a fix value that match the name of the Splunk group for instance: admin
![DualShield MFA Platform > DualShield Configuration [Splunk] > SplunkAtt.png](/download/attachments/35947795/SplunkAtt.png?version=1&modificationDate=1587386357000&api=v2)
- Select "User Principle Name" on NameID Fromat drop down list.
