Integrate HPE GreenLake with Zero Trust Network Access
In this topic, you will find instructions on how to integrate HPE GreenLake with Portnox™ Zero Trust Network Access.
-
You need an HPE GreenLake workspace with an organization. The identity management options used in this topic (SSO connections, and SSO authentication policies) appear only after you create the organization. To get them, create a workspace. Then, click on the ≡ icon to the left of the HPE GreenLake logo, select the option, and create an organization for this workspace.
If your workspace already has services, such as HPE Aruba Networking Central, and you have no organization, you will not be able to create the organization. In such case, contact HPE support. In this case, HPE support must create the organization for you.
-
You must be able to add a record to the DNS configuration of your company’s email domain. HPE GreenLake asks you to add a TXT record there to prove that the domain belongs to you. If you don’t manage DNS yourself, send the TXT record to your DNS administrator when HPE GreenLake shows it. You can continue the configuration only after the record is added.
Create a Portnox Cloud resource configuration
In this step, you will create a configuration in Portnox Cloud that will contain all the information necessary to integrate with HPE GreenLake.
Claim and verify your domain in HPE GreenLake
In this section, you will prove to HPE GreenLake that you own the email domain of your users. HPE GreenLake only redirects users to Portnox Cloud for authentication if their email domain is verified.
Open the HPE GreenLake SSO settings
In this section, you will open the page in HPE GreenLake where you can configure SAML integration settings and provide basic information for the SAML integration.
Copy configuration values from the GreenLake tab to the Portnox tab
In this section, you will copy the values displayed by HPE GreenLake and paste them in the relevant fields in Portnox Cloud.
Copy configuration values from the Portnox tab to the GreenLake tab
In this section, you will copy the SAML metadata URL from Portnox Cloud to HPE GreenLake and finish creating the SSO connection.
Create an authentication policy in HPE GreenLake
In this section, you will create an authentication policy, which sends users from your verified domain to Portnox Cloud for authentication.
Finalize the configuration
In this section, you will finalize the configuration in Portnox Cloud and HPE GreenLake.
You have configured HPE GreenLake to be accessible using Portnox Zero Trust Network Access.
Advanced user administration
HPE GreenLake can create users automatically at their first sign-in and assign their roles based on information sent by your identity provider. This requires the SSO role assignments authorization mode and an additional SAML attribute.
With Local role assignments, you manage users and roles manually in HPE GreenLake. With SSO role assignments, HPE GreenLake creates each user at the first sign-in and applies the roles received from your identity provider in every session. You do not need to add users manually.
For more information, see the following topic in HPE documentation: HPE GreenLake cloud SAML attribute for session-based authentication.



































