Resource Library
Solution BriefsVisibilityRiskOctober 25, 2022

Efficient SSO via SAML Integration: Systems Control Engine (SCE)

SOLUTIONS BRIEF · SAML

Quick Access to ORDR Systems Control Engine (SCE)

IT and Security teams face increasingly complex demands as their large workforces transition between full-time, part-time, outsourced, on-premise, and work-from-home models. Throughout these transitions, consistent and secure access to business applications remains a constant requirement, and single-sign on (SSO) is critical to credential hygiene and management. With the proper implementation of SSO, users can access these applications at any time, unconstrained from location and from any approved device.

Security Assertion Markup Language (SAML) is an open standard that allows identity providers (IDPs) to pass authorization credentials to service providers (SP). SAML enables SSO, a term that means users can log in once, and those same credentials can be reused to log into other service providers.

SAML Service-Provider-Initiated SSO Flow

When a user requests access to ORDR SCE (the service provider), the following exchange takes place with the organization’s identity provider (e.g., Okta, Ping, etc.):

  1. Login Request — the user initiates a login request at ORDR, the service provider.
  2. SAML redirect to IDP — ORDR redirects the user (via their web browser or mobile device) to the identity provider with a SAML request.
  3. Client browser redirected to IDP — the client browser completes the redirect to the identity provider (Okta, Ping, etc.) for authentication.
  4. SAML assertion returned — after authentication (authN), the client receives a response and SAML assertion from the IDP, which is passed back to ORDR to complete sign-on.

ORDR Systems Control Engine (SCE)

With the ORDR SSO integration into existing IDPs like Okta, Ping Identity, Oracle, etc., organizations will have centralized management and access to ORDR SCE. ORDR SCE is an IoT and unmanaged device security platform that will discover every connected device, profile device behavior and risks, and automate response. ORDR not only identifies devices with vulnerabilities, weak ciphers, weak certificates, and active threats, but also those that exhibit malicious or suspicious behaviors. Finally, ORDR automates response for security and networking teams, such as dynamically generating policies and enforcing them on existing infrastructure, or alerting and triggering a specific security or operational workflow.

SAML Integration with ORDR SCE

The ORDR SCE SAML integration supports Service Provider-initiated SSO. This involves the SP creating a SAML request, forwarding the user and the request to the IDP, and then, once the user has authenticated, receiving a SAML response & assertion from the IDP.

When the SP receives a SAML response it will fetch the stored request ID and relay state values and check them against the SAML response’s InResponseTo value and relay state, respectively.

This ensures ORDR receives an expected assertion that is proven by the presence of the request ID and relay state and that the response is intended for ORDR by matching the request ID and relay state.

When Using SP-Initiated SSO, a Modern SAML Solution Will Do the Following:

  • Generate a request ID and include it in the SAML request message
  • Generate a relay state either random application state or just as a simple Cross-site Request Forgery mechanism and include it in the SAML request URL
  • Securely store the two values before redirecting to the IDP

Benefits

  • Quick and secure access to enterprise applications, websites, and data for which they have permission for increased productivity
  • Proper provisioning of access for users
  • Reduction in the amount of credentials one user has for multiple vendors

Case Study

A large healthcare organization with more than 18 hospitals, 220 outpatient locations, 6,000 beds, and 20 patient-centered institutes, serving more than 2.4 million patients, and employing more than 67,500 individuals, is addressing their managed and unmanaged device security risks.

For their environment, they were looking not only to address visibility of managed and unmanaged devices, the ability to automate policy creation, understand behaviors and risk, but they were looking to address multiple stakeholders for the ORDR instance. Using the recent enhancement to support SAML 2.0 as a service provider within ORDR SCE, allows this customer to authorize diverse departments efficient and secure access. They have Security, IT and BioMed involved in using the rich device context to inform business and operational decisions.

ORDR’s real-time dashboard and essential device insights, such as passive and continuous device inventory, mapping of device communication, device risk analysis, and device utilization made ORDR easy to deploy and access for all members of their team.

About ORDR

ORDR makes it easy to secure every connected device, from traditional IT devices to newer and more vulnerable IoT, IoMT, and OT. ORDR Systems Control Engine uses deep packet inspection and advanced machine learning to discover every device, profile its risk and behavior, map all communications and protect it with automated policies. Organizations worldwide trust ORDR to provide real-time asset inventory, address risk and compliance and accelerate IT initiatives. ORDR is backed by top investors including Battery Ventures, Wing, and TenEleven Ventures. For more information, visit www.ordr.net and follow ORDR on Twitter and LinkedIn.

Frequently asked questions
How does SAML-based SSO improve IoT/OT security management?
SAML SSO centralizes user authentication and access controls, eliminating scattered credential management across unmanaged devices. ORDR's Systems Control Engine integrates enterprise-grade authentication standards while reducing friction in resource-constrained IoT/OT environments, maintaining strong security posture without operational overhead.
Can SSO integration work in unmanaged device environments?
Yes. ORDR's approach specifically addresses deployment in unmanaged device environments where traditional access controls are impractical. The Systems Control Engine enables SSO implementation with minimal friction while ensuring that identity and access policies are enforced consistently across your IoT/OT asset inventory.
What are the key benefits of implementing SAML SSO for IoT/OT platforms?
Primary benefits include reduced credential management overhead, simplified user provisioning/deprovisioning, and centralized visibility into access controls. ORDR's SAML integration follows enterprise authentication standards, improving both security posture and operational efficiency without requiring changes to existing unmanaged device infrastructure.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →