Configuring SAML SSO for Dropbox
These steps will guide you through setting up the single sign-on functionality between ADSelfService Plus and Dropbox
Prerequisite
-
Log in to ADSelfService Plus as an administrator.
- Navigate to Configuration → Self-Service → Password Sync/Single Sign On → Add Application, and select Dropbox from the applications displayed.
Note: You can also find Dropbox application that you need from the search bar located in the left pane or the alphabet wise navigation option in the right pane.
-
Click IdP details in the top-right corner of the screen.
-
In the pop-up screen that appears, copy the Login URL click Download Certificate and save it.
Dropbox (Service Provider) configuration steps
-
Login to Dropbox with an administrator’s credentials.
-
Click on Admin Console in the left-pane.
-
In the tab that opens, click on Settings in the left-pane and select Single Sign on.
-
Click the drop-down box against the Single sign-on sign and select either Optional/Required based on your need.
-
Selecting Optional will allow users to log on to Dropbox with Single sign-on or their Dropbox password. Selecting Required will only allow users to login through Single sign-on.
-
Edit Identity provider sign-in URL field and provide the sign-in URL copied in the Step 4 of Prerequisite.
-
Click on the X.509 certificate field and upload the certificate downloaded in the Step 4 of Prerequisite.
-
Click Apply changes to confirm.
-
Copy the Sign-in URL , we will need it in later steps.
ADSelfService Plus (Identity Provider) configuration steps
-
Now, switch to ADSelfService Plus’ Dropbox configuration page.
-
Enter the Application Name and Description.
-
In the Assign Policies field, select the policies for which SSO need to be enabled.
Note:ADSelfService Plus allows you to create OU and group-based policies for your AD domains. To create a policy, go to Configuration → Self-Service → Policy Configuration → Add New Policy.
-
Select Enable Single Sign-On.
-
Enter the Domain Name of your Dropbox account. For example, if you use johndoe@thinktodaytech.com to log in to Dropbox, then thinktodaytech.com is the domain name.
-
Enter the SAML Redirect URL you had saved in Step 9 of Dropbox configuration.
-
Choose the Name ID format that has to be sent in the SAML response. The Name ID format will specify the type of value sent in the SAML response for user identity verification.
-
Click Add Application.
Your users should now be able to sign in to Dropbox Online through ADSelfService Plus.
Note:
For Dropbox, both SP and IDP initiated flows are supported.