How to secure your Shopify Non-Plus stores using CASB
Secure your Shopify Non-Plus stores with the miniOrange CASB solution to protect your store against unauthorized user access by enabling dynamic security restrictions, deep visibility, active threat detection, and granular access controls. In this guide, we will see how you can configure Shopify CASB for your Non-Plus stores.
Step 1: Sign up with miniOrange CASB
Step 2: Selecting Shopify App for Configuration
- After logging in, you should be taken to the miniOrange dashboard page. Locate the "Shopify" tab and click on Add App button.
- Select the Add Authentication Source option from the drop-down menu.
- Mention an Authentication name for the authentication source, and click on Generate Metadata.
- After clicking on Generate Metadata, you will get the metadata details, as shown in the image below. Use this data to configure the SAML application in your Identity Provider (IDP).
- If you would like to view the metadata details again, then you can click on the Show Metadata button.
- Now, Enter the remaining details like the IDP Entity ID, SAML Login URL, SAML Logout URL, and X509 Certificate which you will find in your Identity Provider metadata. Once done, Choose the Binding Type for SSO Request as required. You will find this information in the IDP metadata. However, if you are not sure, please select the HTTP-Redirect Binding as the default configuration.
- Click the Save & Next button once you have filled out all the details.
- You have now successfully configured SAML Authentication with miniOrange CASB.
Step 3: Configuring Shopify Non-Plus Application
- Go to your miniOrange CASB dashboard and then go to Basic Settings section.
- Fill in the following details to configure the Shopify Non-Plus Application:
- Organization Name: Enter the name of your organization.
- Organization Domain: Enter the domain of your organization on Shopify. (Ex: example.com)
- Attribute Key: Enter the Group Attribute Key for the SSO app, which you have configured in the IDP under the SAML attributes section.
- Enable CASB: Select whether you want to enable CASB or not as per your requirements.
- Also, you will have to select whether you want to configure this application for Single Sign On or Multi Staff.
- Click on Save & Next to save your changes.
Step 4: Configuring Policies
Let’s see how to configure policies for Shopify Non-Plus CASB.
- Go to miniOrange CASB Dashboard > Manage Policy. Enter your policy details, like Policy Name and Policy Description.
- Select the “Enable IP Restriction” check box as shown in the image below.
- Follow these steps to configure IP Restriction policy:
1) Select the Allow or Deny option to either permit or restrict certain IP addresses.
2) Click on the Add IP Address icon to create a new field where you can add the IP addresses you want to regulate.
3) Click on the Save & Next button to submit the policy.
- Click on the "Enable Time Restriction" checkbox and enter the Policy Name and Policy Description as shown below in the image.
- Follow these steps to configure Time Restriction policy:
1) Select Allow or Deny to permit or restrict user access during the selected time slot.
2) Select the user's time zone.
3) Select the start and end times for the time-based restriction.
4) Click on the Save & Next button to submit the policy.
- Click on the "Enable Prevent Download" checkbox as shown below in the image.
- Click on the Save & Next button to save the policy.
Step 5: Configuring Groups
Step 6: Edit Screen
- Basic Settings section You can change any configurations if required in the Authentication.
- Suppose you want to configure different authentication sources. In that case, you can simply click on the Authentication Source in the Navigation Bar, where you will be able to add, view & edit authentication sources.
- Group section You can add and configure groups on this screen and view all configured groups. Now, Click on Add New Group.
- You will get a pop-up for adding a new group and you can configure it using the above mentioned steps.
- User Configuration section If you need to configure shopify users for SSO and Multi-stuff.
External References
miniOrange CASB offers a wide variety of security features with flexible scalability, all available at the most affordable price to all types of businesses. Start by signing up now!