Configure SAML for AirWatch


This topic describes how to configure OneLogin to provide SSO for AirWatch using SAML.

Note: before starting this process, ensure you have your AirWatch Group ID, which is found on the AirWatch Organization Group tab listing under Group ID.

OneLogin

  1. Navigate to Administration > Applications > Applications, then click the Add App button and and select AirWatch (Custom Domains). Rename the app if you wish, then click Save.
  2. Navigate to the Configuration tab and choose Airwatch as your Type.

  1. Choose Login URL, then enter it using the following formula: https://{yourairwatchdomain}/AirWatch/Login?GID={GID}"}
  2. Add your AirWatch domain, then click Save.
  3. Navigate to the Parameters tab and ensure that the UID parameter is mapped to username. Click Save.

  1. Navigate to the SSO tab, then copy down the Issuer URL and SAML 2.0 Endpoint and paste them in a safe place for later retrieval.
  2. Choose View Details under the X.509 Certificate dropdown. Scroll down to Download, then store the certificate in a safe place on your computer.

AirWatch

  1. Navigate to the AirWatch administration panel and enable SAML for Authentication, then ensure that Enable SAML Authentication for includes Admin, Enrollment, and Self-Service Portal.

  1. Navigate to the SAML section and use the following values:

  1. Navigate to the User section and ensure that the Attributes match the following:

OneLogin

  1. Navigate back to OneLogin and add the AirWatch app to a test user, then assume the user and log in to test the connection.