SAML User Provisioning

You can enable user provisioning to automatically create SAML-authenticated users in Tenable Security Center by importing user accounts from your SAML identity provider. When user provisioning is enabled, users who log into your SAML identity provider are automatically created in Tenable Security Center. For more information about SAML authentication in Tenable Security Center, see SAML Authentication.

Tip: Review the Tenable SAML Configuration Quick-Reference guide for a step-by-step guide of how to configure SAML for use with Tenable Security Center.

If you enable user provisioning and a user who does not have a Tenable Security Center user account logs in using your SAML identity provider, Tenable Security Center automatically creates a user account for them in Tenable Security Center.

Tenable Security Center creates users using data from attribute fields you map to the corresponding fields in your SAML identity provider. If you enable User Data Sync, each time a user logs into Tenable Security Center using your SAML identity provider, Tenable Security Center updates any mapped attribute fields in Tenable Security Center with values from the fields in your SAML identity provider. For more information about User Data Sync, see SAML Authentication Options.

Note: If you want to edit a Tenable Security Center user that was created via SAML user provisioning and you enabled User Data Sync, edit the user in your SAML identity provider. Otherwise, the Tenable Security Center user data sync overwrites your changes the next time the user logs in to Tenable Security Center using your SAML identity provider.

Note: If you want to delete a Tenable Security Center user that was created via SAML user provisioning, delete the user from your SAML identity provider. If you delete a user in Tenable Security Center that was created via SAML user provisioning without deleting the user in your SAML identity provider, Tenable Security Center automatically re-creates the user in Tenable Security Center the next time they log in using your SAML identity provider.

For more information, Configure SAML User Provisioning.