Configuring SSO
In this section, we'll go through a step-by-step guide to configure SAML SSO on Microsft Azure for Enterpret. You can read more about using SSO on Enterpret here.
NOTE: You might require elevated permissions on Azure to perform the following steps. Please contact your account admin if you don't find any of the referred settings on your Azure dashboard.
Creating an Application
Navigate to Applications > Enterprise Applications on your Azure dashboard
On the Applications page, click on New application
Next click on Create your own application
On the modal that pops up, provide the following input:
Add
Enterpret SAML App
as the application nameSelect
Integrate any other application you don't find in the gallery (Non-gallery)
as the application type.Click On Create
Configure SAML Application
Under Manage, click on Single sign-on.
Select SAML from the option
Provide the following input in the Basic SAML Configuration section:
Identifier (Entity ID):
urn:amazon:cognito:sp:us-east-2_kLiRrPBis
Reply URL (Assertion Consumer Service URL):
https://enterpret-prod.auth.us-east-2.amazoncognito.com/saml2/idpresponse
You can leave Sign-on URL, Logout URL, and Default RelayState empty.
Note: For Idp-initiated SSO, you will need to provide the relay state value. Please reach out to Team Enterpret to get the value.
4. Adding claims to your SSO Aplication
Verifying the Correct Source Attribute for Email
Before proceeding with attribute configuration, ensure that the correct attribute is mapped to the email claim.
Navigate to Microsoft Entra ID > Users > Select a sample user.
Check the
User Principal Name (UPN)
andMail
attributes.If users only have their email in
User Principal Name (UPN)
, mapuser.userprincipalname
.If users have valid email addresses in
Mail
, mapuser.mail
to the email claim, instead.Confirm with your IT admin if UPN is always an email format in your organization before finalizing the mapping.
Adding Claims to your SSO application
Under Attributes & Claims, click on Edit icon
Click on Add new claim
Add Name as
email
Select Source as
Attribute
Add Source attribute as the verified email attribute (
user.userprincipalname
oruser.mail
) based on the verification step above.Namespace can be left empty
Click on Save Icon on the top.
Image or attachment is not accessible.
You have successfully created an Application that would allow Microsoft Azure to communicate with Enterpret! As the next steps, you'll need to copy relevant details from the created app and configure it on the Enterpret dashboard.
Copying Metadata URL Values
On the Single sign-on page , you can copy the App Federation Metadata URL from SAML Certificates section, this is the metadata URL that you will need to configure on the Enterpret dashboard.