Description

This article acts as SSO onboarding instruction docket for customers who want to onboard SSO for accessing juniper.net applications. When in doubt, engage with your Service Manager / Technical Service Advisor (TSA) or Sales Engineer for more details. 

 Attention: *SAML integration already supported with Mist, Routing Assurance and Apstra Cloud Services and therefore already supports SSO. 

Solution

This document outlines key information for Juniper Networks customers related to enabling Inbound Federation with Customer Identity Provider (IdP) (aka Single Sign-On /Fed SSO).  

  

By enabling SSO with Juniper, customers can access multiple Juniper applications using a single set of credentials, authenticating users from their respective organization IdP, eliminating the need to setup, manage and remember a local Juniper username and password.   

Important Guidelines:  

  • Federated SSO will be setup for a customer at Domain-Level.   
  • To initiate SSO onboarding, please reach out to your Service Manager/TSA or Sales Engineer with the technical information requested below.
  • SSO would only work for users who have an approved registered account with Juniper. Therefore, even after SSO is enabled, not all users can access Juniper products even though they are from the same corporate domain. 
  • In scenarios where a single customer has multiple “Domains”, Fed SSO can be setup for their multiple “Domains”. 
  • Only corporate domains can be setup for Fed SSO and not public domains.  
  • Individual Customer end-users must register with Juniper Networks (using existing registration process). In case the end-user has not registered with Juniper, this would result in an error while signing in via federation with Juniper products and services. 
  • Customers will be responsible for maintaining their end-user access and ensuring that they disable employee access from their end once they leave the organization.  
  • Customer’s IdP endpoint should always be accessible to the user’s client devices.   
  • For testing purposes, Fed SSO can be setup on the customer’s sandbox environment. Once customer tests and validate the SSO functionality, then it’ll be configured for their production environment.  
  • To initiate federation with customer IdP for their Domain/s: 
    1. Customers must meet the “Eligibility Requirements” listed below. 
    2. Request Service Manager (SM) / Technical Services Advisor (TSA) / Sales Engineer (SE) to initiate SSO onboarding for the customer. 
    3. A set of technical info must be documented (listed below and referred to as “Onboarding Request Form Template”) and needs to be shared with your SM / TSA as part of the SSO onboarding process. 
  • Note: In case you are using XML tool (xml.juniper.net), kindly use a Juniper registered group/shared username and request for exclusion via Service Manager for this shared username as your individual access to XML tool will be impacted once Federated SSO is configured for your domain. Service Manager would then request via internal ticket for an exclusion of this username from SSO. 
  • Whenever customer offboards SSO, the registered users would be required to reset their Juniper account password to access Juniper’s products and services. 
  • The lead time for SSO Onboarding can be 2-6 weeks after Service Manager has created an internal request with support (i.e. coordination and ensuring timely information exchange) by Service Manager for the customer account and customer’s technical POC. 
  • MFA will be managed on customers IdP only.  

Eligibility Requirements  

The following eligibility Requirements should be met prior to requesting federation with customer IdP for an organization:  

Description
  1. Premium or Advanced Services Customer with Service Manager or Technical Services Advisor supporting the customer  
  1. Using SAML 2.0-based IdP connection or OIDC-based IdP connection
  1. Customer assigns a primary technical POC who can provide required technical info to Juniper, setup configuration on their IdP end, and coordinate with the Juniper team, if required  

 

Onboarding Request Form Template  

The customer can download the form and submit the technical information listed below to the Service Manager, who will attach this document to the internal ticket when raising the SSO request for the customer.  

#Required Customer Info to request "Federation with customer Idp" for a Customer Corporate Domain   Customer’s Input   
1Customer Point of Contact Name  
2Customer Point of Contact Email Address 
3Customer Point of Contact Phone # 
4Organization Name  
5Domain/s 
6Test Users:  Names / Email Addresses / Phone #s (1-2 Testers recommended) 
7SAML 2.0-based IdP connection OR OIDC-based IdP connection .
8Group / Shared usernames to be excluded from SSO  
  If SAML 2.0-based IdP connection:  
1Issuer URL / EntityID 
2Name ID Format (Email / Unspecified) 
3SAML2.0 metadata: (File or a URL if published online)  
4Signing Algorithm (Name, example: SHA-1 or SHA-256 (preferred)  )
5Certificate (PEM or DER format)  
6SSO URL 
7Custom Logout URL, if any  
8Attributes: EmailAddress
If OIDC-based IdP connection:    
1OIDC Client ID   
2Supported Client Authentication: Client secret or public/private key pair (preferred) 
3OIDC metadata: (file or a URL if published online) 
4Issuer 
5Authorization End-Point URL  
6Token End-Point URL 
7JWKS endpoint URL 
8User Info endpoint URL

 

For more details, please reach out to your respective Service Manager or TSA or Sales Engineer / Account Manager.  

 

 

 

Modification History

2025-23-07: added PDF form
2025-07-18: Article created