After obtaining your SAML identity provider certificate and URL, the account Owner can set up, test, and enable the Single Sign-on (SSO) configuration in New Relic.
Access to this feature depends on your subscription level.
Master and sub-accounts
If your account has sub-accounts, typically you will set up the SSO configuration on the master level only. The sub-account users will still be able to log in through SSO because they will inherit the master account's SAML SSO configuration. If you need to configure multiple accounts with separate SAML identities (for example, with partnership accounts), use the Custom Entity ID feature.
To help ensure security and account for network time and clock skews, configure your SAML identity provider's validation responses to the shortest time period that is practical (for example, 5 minutes). New Relic allows a maximum of 30 minutes.
To set up your SSO configuration:
- Go to account.newrelic.com > (account dropdown) > Account settings > Security and authentication > Single sign on.
- From the SAML Single Sign On page, review your New Relic SAML Service Provider details.
- To upload your SAML Identity Provider certificate, select Choose File, then follow standard procedures to select and save the file.
- Specify the Remote login URL that your users will use for single sign on.
- If your organization's SAML integration provides a redirect URL for logout, copy and paste in (or type) the Logout landing URL; otherwise leave blank.
- Save your changes.
If your organization does not use a specific redirect URL, New Relic automatically provides a logout landing page.
After you correctly configure and save your SSO settings, the Test page automatically appears. After each test, New Relic returns you to the SAML SSO page with diagnostic results.
To go back and change your configuration settings, select 1 CONFIGURE.
When testing successfully completes, a link appears that you can use on your company's landing page for easy Single Sign On with New Relic. As an additional security measure, users cannot sign in until they complete the email confirmation that New Relic sends automatically.
After your users select the link in their confirmation email, they can sign in securely with your organization's assigned user name and password. From there they can select any application they are authorized to use, including New Relic.
If you disable SAML SSO, New Relic automatically flags all of your Pending users as Active. If you decide to re-enable SAML SSO later, New Relic automatically flags all users except the Owner as Pending, and they will need to confirm their account access by email.
Add a logout URL for session timeouts
New Relic's Session Configuration feature requires a logout URL for SAML SSO-enabled accounts. If you have already configured, tested, and enabled SAML SSO without a logout URL, New Relic automatically prompts the account Admin to notify the account Owner. In addition, if you are the account Owner, New Relic automatically provides a link from Session configuration to go directly to SAML Single Sign On and add a logout URL.
The logout URL cannot contain
newrelic.com anywhere in the URL.
The Session Configuration feature also includes the option to select an automatic timeout for SAML-authenticated browser sessions to be re-authenticated.
For more help
Additional documentation resources include:
- Adding users to SAML accounts (using New Relic's SSO feature to require users to confirm their account)
- Maintaining SSO settings (updating your SAML certificate, SSO URLs, or other settings)
- Deleting the SSO configuration (removing your SSO integration with New Relic completely)
- SAML service providers (SAML service providers that New Relic supports for SSO integration)
- Setting session timeouts (procedures to view or select an automatic session timeout for any account, and an automatic browser re-authentication time for SAML-enabled accounts)