SAML SSO & MFA Configuration
Budget: ₹100 – ₹400 INR
I need my portfolio of internally hosted web applications moved over to a true single sign-on experience. The protocol is fixed—SAML 2.0—and the sign-in flow must trigger multi-factor authentication every time a user authenticates through the chosen identity provider. Whether you prefer Azure AD, Okta, Ping, or another standards-compliant IdP is up to you, as long as the result is a seamless, secure SAML exchange.
The work involves wiring up the SAML trust between the IdP and each service provider, importing and validating metadata, mapping attributes, and testing the full login/logout flow so that one successful MFA challenge unlocks all apps in the same browser session. Please also hard-fail any attempt that bypasses MFA.
Deliverables
• Functional SAML 2.0 connection for every web application in scope
• Enforced MFA within the SAML flow (TOTP, push, or hardware key—whatever the IdP supports)
• Step-by-step documentation covering configuration, attribute mapping, certificate rollover, and routine maintenance
• A concise test report proving successful SSO and MFA enforcement for at least three user accounts (normal, admin, and disabled)
I’ll provide access to the web app dashboards, DNS, and an empty tenant (or existing) IdP environment once we agree on the exact toolset. Feel free to suggest improvements, but the final outcome must keep SAML + MFA at its core and leave our end users with a single, secure login.
The work involves wiring up the SAML trust between the IdP and each service provider, importing and validating metadata, mapping attributes, and testing the full login/logout flow so that one successful MFA challenge unlocks all apps in the same browser session. Please also hard-fail any attempt that bypasses MFA.
Deliverables
• Functional SAML 2.0 connection for every web application in scope
• Enforced MFA within the SAML flow (TOTP, push, or hardware key—whatever the IdP supports)
• Step-by-step documentation covering configuration, attribute mapping, certificate rollover, and routine maintenance
• A concise test report proving successful SSO and MFA enforcement for at least three user accounts (normal, admin, and disabled)
I’ll provide access to the web app dashboards, DNS, and an empty tenant (or existing) IdP environment once we agree on the exact toolset. Feel free to suggest improvements, but the final outcome must keep SAML + MFA at its core and leave our end users with a single, secure login.