SAML integration - one-way communication query

Sarah Mohd Nor 0 Reputation points
2025-01-10T02:53:18.9833333+00:00

Hi, my customer is planning to integrate Cisco Secure Access with Entra ID for the SAML part.

https://docs.sse.cisco.com/sse-user-guide/docs/configure-azure-for-saml

https://learn.microsoft.com/en-us/entra/identity/saas-apps/cisco-user-management-for-secure-access-provisioning-tutorial

We have received verbal confirmation from Cisco Product Team that it is indeed a one-way communication from Cisco side. Which means Cisco will not be able to modify anything on the Microsoft end. However, the customer is asking if there's any proof from Microsoft which will support this statement. Thank you so much.

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
23,066 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Goutam Pratti 1,475 Reputation points Microsoft Vendor
    2025-01-10T21:41:41.2966667+00:00

    Hello @Sarah Mohd Nor ,

    Thank you for reaching out Microsoft Q&A.

    I understand you received verbal confirmation from Cisco Product Team that it is indeed a one-way communication from Cisco side. Which means Cisco will not be able to modify anything on the Microsoft end. However, the customer is asking if there's any proof from Microsoft which will support this statement.

    Cisco will not be able to modify and configure on the Microsoft (Microsoft Entra ID) end, and similarly, Microsoft (Microsoft Entra ID) cannot modify the configurations on Cisco's side. Only Cisco can make configuration changes to their application, and similarly, only Microsoft Entra ID can make configuration changes on its side. This is because Microsoft (Microsoft Entra ID) acts as the Identity Provider (IdP) for authentication and authorization to Cisco. While there is no official documentation explicitly proving that Cisco will not be able to modify anything on the Microsoft end.
    You can refer to the below documentation for the actual flow and configuration details.

    for additional information follow: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/add-application-portal-setup-sso
    https://learn.microsoft.com/en-us/entra/identity-platform/single-sign-on-saml-protocol

    Hope this helps. Do let us know if you any further queries.


    If this answers your query, do click Accept Answer and Yes for was this answer helpful. And, if you have any further query do let us know.

    Best Regards,
    Goutam Pratti.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.