Tutorial
Configure IBM Security Guardium user authentication with IBM Security Verify
Implement a centralised enterprise application authentication systemIBM Security Guardium is a family of data security software in the IBM Security portfolio that protects sensitive on-premises and cloud data. The flagship product in this family is Guardium Data Protection (GDP), which helps organizations to discover, protect, and monitor sensitive data elements and activities, and helps remediate data violations.
IBM Verify SaaS is an IAM solution provided as a SaaS that adds deep context, intelligence and security to decisions about which users should have access to your organization’s data and applications, on premises or in the cloud.
Learning objectives
In this tutorial, you'll learn how to configure Verify SaaS as an identity provider (IdP) for Guardium. You can learn more about high-level generic SAML SSO configuration in the IBM Security Guardium documentation.
Estimated time
Completing this tutorial should take about 30 minutes.
Prerequisites
- IBM Security Guardium 11.5 collector appliance, with access to an
adminuser role to perform SSO management - IBM Security Verify Subscription, with access to an
adminuser role to perform custom application creation and activation
Use case
Verify SaaS can be configured in Guardium Data Protection to manage users with the enterprise user directory without replicating them on Guardium.
By integrating with Verify, Guardium user authentication can be completed using SAML-based single sign-on (SSO). This feature enables you to include Guardium as part of a centralised enterprise application authentication system.
Steps
The high-level steps to configure Verify SaaS include the following:
- Configure the Guardium portal.
- Generate the service provider metadata.
- Create a Verify SaaS custom application.
- Configure the service provider.
- Log in from IBM Security Guardium.
Step 1: Configure the Guardium portal
You first need to switch the portal authentication configuration to SAML SSO.
- Log in into Guardium and go to Setup > Tools and Views > Portal.
Note that you will need to scroll to view the Portal menu option.

- Select the Single Sign on (SAML) radio button. The "Configure SAML authentication" window opens.

- Select the IdP metadata file, as shown in the following image. Update the other configuration details as provided by your Verify administrator.
Note: In this configuration, most of the settings are left as their default values. However, you can edit them based on your Verify policies. The How to authorize field has two options: Local refers to users that are available locally in Guardium appliances; User attributes refers to users from LDAP of the IdP used by Verify SaaS. Matching will be based on the attributes configured for Guardium, including Role, First Name, Last Name or Email, or any combination of those attributes.

- Click Save to save the configuration.
The Setup page now shows that SSO has been configured. The service provider metadata file will be automatically downloaded.

Step 2: Generate the service provider metadata
The service provider (SP) metadata file can be downloaded again from the configuration page in case the automatically downloaded file is not traceable or is lost.
- In the Guardium menu, click Setup > Portal.
- In the GUI Authentication section, click Configure.
- In the "Configure SAML authentication" window, click Generate SP metadata.

Note: When the configuration is complete, you must change the authentication mode back to Local. You have not yet configured Verify SaaS with Guardium SP details and if you log out of Guardium, you will not be able to log back in. You will update the SSO mode as soon as you have configured Verify.
Step 3: Create a Verify SaaS custom application
- Log in to Verify SaaS as an admin user.
- In the left menu, click Applications > Applications. The Applications window opens.
- Click Add application. The Select Application Type window opens.

- Click Custom Application. You need to create a custom application because Guardium is not a pre-packaged application in Verify SaaS.

- Click Add application. The Custom Application page opens.
- On the General tab, enter a name for the application (for example,
IBM Guardium Data Protection, and click Add owner.
- Add an application owner from Verify SaaS.
Step 4: Configure the service provider
- On the Custom Application page, click the Sign-on tab. Using the SP metadata file (see Step 2, above), update the following fields:
- Provider ID: Enter the hostname of the Guardium appliance.
- Assertion Consumer Service URL: Enter the Guardium appliance URL. (Note: In this tutorial's infrastructure configuration, the hosting has been routed through a firewall, and therefore the public, private, and hostname URLs have each been included in this configuration. Normally, you would only need to include the public access URL in this field.)

- Service provider SSO URL: Enter the Guardium GUI URL and port number.
- Single logout URL(HTTP-POST): Enter the value from the SP metadata file. Normally, this value will be
<Guardium URL>/saml/slo.
- Leave the other fields in their default settings. When you have finished updating, click Save.
Note: When you save the sign-on details, the Entitlements tab displays in the Custom Application page. For this tutorial configuration, we have authorized Guardium local users, and therefore accessmgr and guardium user are listed as the authorized users from Verify SaaS. Alternatively, you can authorize users with specific roles from the enterprise LDAP.

- Click Save to save the Verify SAML-based SSO for Guardium.
Step 5: Log in from Guardium
- Log in to Guardium. In the left menu, click Setup > Tools and Views > Portal.
- In the GUI Authentication panel, select the Single sign on (SAML) radio button.

- Log out from Guardian and then log in again. Note that the login page is redirected to the Verify SaaS-based login page.

- Log in with the users configured in Verify (for example, accessmgr or guardium user, as described in step 4, above). The Guardium welcome page is displayed.
You can now continue with your Guardium activities.
Summary
In this tutorial, you have configured IBM Security Verify SaaS as an identity provider (IdP) for IBM Security Guardium. The configuration is based on SAML SSO and can be extended to any other SAML-based IdP using the same process.
Now that you've seen how to integrate IBM Security Verify and IBM Security Guardium, explore more security options in the IBM suite of security and data protection.