Forum Discussion

linztric's avatar
linztric
Day Hiker II
22 hours ago

Entra ID SAML2 SSO on FlashArray (Purity//FA 6.12.3), including fleets

Hi everyone,

Here is a working setup for single sign-on from Microsoft Entra ID to a FlashArray, tested on Purity//FA 6.12.3, which is the newest version at the time of writing. It follows the Microsoft tutorial for Pure Storage SSO (https://learn.microsoft.com/en-us/entra/identity/saas-apps/pure-storage-sso-tutorial) and adds the fixes I needed to get the login test to pass. It also covers adding more arrays and fleets.

Two things that break the login if you skip them

  • The gallery app ships with role names that do not match the FlashArray role names. If you do not rename them, the login test fails because the array cannot find the role (Step 6).
  • The claims must have no namespace URI (Step 5).

What you need

  • An array admin login
  • Entra admin rights (Enterprise applications and App registrations)
  • The Pure Storage SSO app from the Entra App Gallery
  • A user or group to assign

Overview

  1. Create a certificate on the array
  2. Configure SAML2 SSO on the array
  3. Entra app and the array certificate
  4. Load the Entra signing certificate on the array
  5. Claims (delete the namespace URI)
  6. Fix the app role names
  7. Assign, test and enable

Plus: more arrays and fleets, and a troubleshooting list at the end.


Step 1: Create a certificate on the array

The array needs its own RSA certificate to sign SAML requests and decrypt assertions. Do not use the management certificate: it is EC 256 and caused a 500 error for me.

purecert self-signed create saml-sp --common-name myarray.pure --days 365

purecert list

The saml-sp row should show self-signed, rsa, 2048. Note the expiry date: SSO signing stops working when it expires.


Step 2: Configure SAML2 SSO on the array

Go to Settings › Access › Users and Policies › SAML2 SSO and edit the configuration.

  1. Array URL: the array FQDN, for example https://myarray.pure/.
  2. Signing Credential and Decryption Credential: type the certificate name saml-sp. Do not paste certificate text.
  3. Switch on Sign Request and Encrypt Assertion.
  4. IdP Entity ID, URL and IdP Metadata URL: copy them from the Entra app (Set up Pure Storage SSO section).
  5. Keep Enabled off for now and save.

Without credentials, saving fails with "Must provide signing credential when signed request is enabled" and the same message for decryption.

The GUI can silently keep management, so check the result in the CLI:

puresso saml2 list

puresso saml2 test

Both credential columns must show saml-sp. If not, set them directly:

puresso saml2 setattr Entra-ID --signing-credential saml-sp --decryption-credential saml-sp

This can print "Certificate claim does not exist." even though the values were applied, so trust the list output.


Step 3: Entra app and the array certificate

  1. In the Entra admin center go to Enterprise apps › New application, search Pure Storage SSO and add it.
  2. Open Single sign-on › SAML › Basic SAML Configuration. Set Identifier to the array's SP Entity ID and Reply URL to the array's Assertion Consumer URL. Both are shown in the array's SAML2 SSO dialog, so copy them from there.
  3. On the array, open the certificates page and download saml-sp. Rename the extension from .crt to .cer.
  4. In the Entra app go to Single sign-on › SAML Certificates › Verification certificates › Edit, tick Require verification certificates, and upload the .cer.
  5. Because Encrypt Assertion is on, also import the same .cer under Token encryption and activate it (see the token encryption guide under Links).

Check that you exported the right certificate:

openssl x509 -in saml-sp.cer -noout -subject -enddate

The subject must show the common name you used in Step 1, not the GUI certificate.


Step 4: Load the Entra signing certificate on the array

The array needs Entra's signing certificate to validate the response. If this is empty the array test still shows OK, but a real login fails.

  1. In Entra open Single sign-on › SAML Certificates and download Certificate (Base64).
  2. Open the file, copy everything including the BEGIN CERTIFICATE and END CERTIFICATE lines.
  3. In the array's SAML2 SSO dialog click Edit next to Verification Certificate and paste it.

CLI alternative:

puresso saml2 setattr Entra-ID --verification-certificate


Step 5: Claims (delete the namespace URI)

In the Entra app go to Single sign-on › Attributes & Claims › Edit. Open each claim, clear the Namespace field completely, and make sure the names match exactly:

  • dn: user.onpremisesdistinguishedname
  • email: user.mail (or user.userprincipalname for UPN)
  • family_name: user.surname
  • given_name: user.givenname
  • purity_roles: user.assignedroles (required for array level SSO)

Step 6: Fix the app role names

The Pure Storage SSO gallery app is set up incorrectly for its role names. It ships readonly_role, ops_admin_role, storage_admin_role and array_admin_role with an empty value. The names must match the FlashArray role names exactly, otherwise the login test fails because the array cannot find the role.

The roles are edited in App registrations, not in the Enterprise application:

  1. Go to App registrations › All applications and search for the app name.
  2. Open App roles and click a role.
  3. In Display name, remove the _role suffix.
  4. In Value, enter the role name, for example array_admin.
  5. Click Apply and repeat for the other roles.
  • array_admin_role → Display name: array_admin, Value: array_admin
  • storage_admin_role → Display name: storage_admin, Value: storage_admin
  • ops_admin_role → Display name: ops_admin, Value: ops_admin
  • readonly_role → Display name: readonly, Value: readonly

Leave msiam_access as it is.


Step 7: Assign, test and enable

  1. In the Entra app go to Users and groups › Add user/group, pick the user, click Select a role and choose one of the renamed roles. Only one role per assignment.
  2. On the array open the SAML2 SSO dialog and click Test. All lines must be green and the first two must show saml-sp.
  3. Click E2E Test, sign in with the assigned user, then click Check E2E Test Result.
  4. If it passes, switch Enabled on and save. The login page now shows Click for Single Sign-On and a Local Access link.

Tip: Keep a working local admin login in case something on the Entra side breaks or a certificate expires.


More arrays and fleets

Each array needs its own certificate, and that certificate must be uploaded to Entra under Verification certificates, next to the ones from the other arrays.

You do not need a new Enterprise application per array. If you use Fusion / fleet manager, enable Trust Other SAML Service Providers In Fleet in the SAML2 SSO configuration and apply these settings on each additional array:

  1. Create the certificate on that array (Step 1) with its own common name.
  2. Use the same SSO configuration name as on the first array.
  3. Array URL: the FQDN of the new array.
  4. SP Entity ID: set it to Manual and paste the SP Entity ID of the first array. All fleet members must use the same SP Entity ID.
  5. Signing Credential and Decryption Credential: saml-sp, the certificate of this array. Switch on Sign Request and Encrypt Assertion.
  6. Identity Provider fields and Verification Certificate: the same values you used on the first array.
  7. In the Entra app, add a second Reply URL with the Assertion Consumer URL of the new array, and upload the new array's saml-sp .cer under Verification certificates.
  8. Run Test and E2E Test before enabling.

After that you can sign in on the other arrays with the same Entra users, roles and claims.

Note: If you use Encrypt Assertion on several arrays, check this: Entra token encryption uses one active certificate per application, so test each array with the E2E test.


Troubleshooting

  • Save fails: must provide signing or decryption credential: Create saml-sp and enter its name in both fields
  • Red error echoes a long MIID... string: You pasted certificate text. Type the certificate name instead
  • Test shows management as credential: Run puresso saml2 setattr as in Step 2
  • 500 Internal Server Error when starting login: The credential was the EC management certificate. Switch to the RSA saml-sp certificate
  • Login test fails, role not found: Rename role display name and value in App registrations (Step 6)
  • Login fails or user has no role: Clear the claim namespaces and check purity_roles = user.assignedroles (Step 5)
  • Verification certificate shows - in the test: Paste the Entra Base64 certificate (Step 4)

If you do not need signed requests or encrypted assertions, you can switch off Sign Request and Encrypt Assertion and skip the certificate steps.


Links

  • Configure Pure Storage SSO for Single sign-on with Microsoft Entra ID (https://learn.microsoft.com/en-us/entra/identity/saas-apps/pure-storage-sso-tutorial)
  • Configure Microsoft Entra SAML token encryption (https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/howto-saml-token-encryption)
  • Manage certificates for federated single sign-on (https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/tutorial-manage-certificates-for-federated-single-sign-on)
  • App roles UI (https://learn.microsoft.com/en-us/entra/identity-platform/howto-add-app-roles-in-apps#app-roles-ui)

Hope this saves someone some time. Questions and corrections are welcome.

No RepliesBe the first to reply