How to configure Radancy Hiring Events in your SAML IDP

 

The following configurations must be done in order to successfully set up Radancy Hiring Events as a service provider in your identity provider.

1) Point to Radancy's Metadata

Radancy's SAML metadata is found at https://app.brazenconnect.com/sso/saml/metadata.

2) Specify the correct attribute name and format.

Radancy requires all SAML attributes to have the Object Identifier (OID) as the name and uri as the name format.

<saml:Attribute Name="urn:oid:0.9.2342.19200300.100.1.3"
  NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
    <saml:AttributeValue>user@example.com</saml:AttributeValue>
</saml:Attribute>

Required fields

Friendly Attribute Name OID Attribute Name Definition
mail urn:oid:0.9.2342.19200300.100.1.3 The preferred or primary email address for the user. Radancy will use the first value it finds in a claim.
givenName urn:oid:2.5.4.42 Name strings that are the part of a person's name that is not their surname.
surname urn:oid:2.5.4.4 The surname or last name of the user.

Optional fields

Radancy has an OID repository (1.3.6.1.4.1.47993) that defines fields specific to Radancy's system. These are optional fields that do not need to be provided in order to successfully provision a user in Radancy.

To send a value as one of these fields to Radancy, simply make the attribute name the corresponding OID value.

Friendly Attribute Name OID Attribute Name When to use Definition
userId urn:oid:1.3.6.1.4.1.47993.1.1.2 This is needed if the system cannot guarantee that a user's email address will remain the same. The identifier for this user in the external system. Radancy will use the first value it finds in a claim.
ianaTimeZone urn:oid:1.3.6.1.4.1.47993.1.1.3 To set the timezone for the user other than the default. The user's preferred time zone such as "America/New_York". Radancy uses IANA Olson time zone names. If one is not provided, the user's time zone is set to "US/Eastern". Users will have the ability to set a timezone within Radancy.

See the example below for a valid AttributeStatement in the SAML response.

<saml:AttributeStatement>
    <saml:Attribute Name="urn:oid:0.9.2342.19200300.100.1.3"
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>user@example.com</saml:AttributeValue>
    </saml:Attribute>

    <saml:Attribute Name="urn:oid:2.5.4.4"
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>Test Last Name</saml:AttributeValue>
    </saml:Attribute>

    <saml:Attribute Name="urn:oid:2.5.4.42"
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>Test First Name</saml:AttributeValue>
    </saml:Attribute>

    <!-- Optional fields -->
    <saml:Attribute Name="urn:oid:1.3.6.1.4.1.47993.1.1.2"
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>Test External ID</saml:AttributeValue>
    </saml:Attribute>

    <saml:Attribute Name="urn:oid:1.3.6.1.4.1.47993.1.1.3"
      NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
        <saml:AttributeValue>America/New_York</saml:AttributeValue>
    </saml:Attribute>
</saml:AttributeStatement>

3) The NameId format must be persistent

Radancy's SSO configuration requires the NameId format to be persistent. This is a requirement of Radancy's system and cannot be changed.

The NameId can be found within the Subject element in the SAML response.

<saml:Subject>
    <saml:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">
        NameId
    </saml:NameID>
</saml:Subject>

Resources on how to specify a persistent NameId

Was this article helpful?
0 out of 0 found this helpful