SAASPASS Integration

Configuring SAASPASS Integration

Configuring SAASPASS integration with DefensX requires 2 basic steps:

  • Create a Generic OIDC secure application on SAASPASS

  • Update the integration settings in DefensX Backend based on the created application credentials

Creating the application in SAASPASS

After logging into the SAASPASS backend you need to switch to the Company Mode from the top-right menu first and select the company you want to add the application.

Under the Applications section click on the Add Secure Applications button.

saaspass1

Click on the OAUTH & OIDC (OPENID CONNECT) button first and then click to ADD button under the Generic OIDC application.

On the next screen:

  • Name: Click on the edit icon on the application name and change it by a more descriptive one like DefensX SaasPass

  • Callback URL: Enter https://cloud.defensx.com/saaspass/callback

  • Scopes: Make sure it is selected as openid,email

then click on the ▶ SAVE AND RUN button.

saaspass2

After creating the application you need to select which user groups can use the application. Click on the USER AUTHENTICATION MANAGEMENT tab and click on + ASSIGN OTHER GROUPS if you want to add more groups to the newly created application.

On the last step, click on the INTEGRATION tab and then click on the APP KEY & PASSWORD from the left menu. Please keep this screen open and continue the integration part in DefensX backend.

saaspass3

Configuring the integration in DefensX

After creating the application in SAASPASS, you should configure it in DefensX Backend as well with the following steps:

  • Switch to the customer context that you want to configure the integration

  • Navigate to the Settings → SAASPASS Integration menu

  • Copy the CLIENT ID from SAASPASS and paste it into the SAASPASS Client ID field

  • Copy the CLIENT SECRET KEY from SAASPASS and paste it into the SAASPASS Secret Key field

  • Copy the PUBLIC KEY from the SAASPASS and paste it to the SAASPASS Certificate field

  • Click on the Save button.

  • Navigate to the Settings → Globals menu and make sure that "SAASPASS Signin" option is enabled. You can also temporarily disable the integration without removing the application completely.

Testing the integration

Now you can test the integration when logging into the DefensX Backend with admin rights. If your account email has admin rights in DefensX Backend, click on the Sign-in with SSO button first and enter your email address. It will automatically redirect you to the SAASPASS for the authentication. After a successful authentication process, you’ll automatically sign into your DefensX profile.