EM SAML SSO Integration
Introduction
Entity Management (EM) supports Security Assertion Markup Language (SAML) Single Sign-On (SSO) and the following information provides the necessary steps required to configure SAML SSO. EM supports integration with Azure AD for SAML SSO out-of-the-box. This document covers the most common configuration components. Refer to the information provided by Azure AD for additional considerations and configurations.
How does SAML SSO work?
SAML SSO works by transferring user identity from the identity provider (IdP) to the service provider (SP) through an exchange of digitally signed XML documents (i.e., requests, responses).
The authentication sequence followed using SAML SSO integration with EM is:
- The end user initiates log in to the Kingland application.
- Request is received by the Service Provider (Kingland).
- Service Provider creates a SAML request to the Identity Provider (Azure AD).
- Identity Provider identifies the user, creates a SAML response and sends it to the Service Provider.
- Service Provider verifies the SAML response and logs the user in.
What information does Kingland provide?
Kingland provides the following data elements to assist in configuring the SAML SSO integration with EM.
Value | Example | Description |
|---|---|---|
Sign-on URL | <url>/saml/login_success | The location where the end user connects to the Service Provider and begins the log-in process. |
Reply URL | <url>/saml/SSO | The location where the authorization server sends the user once the app has been successfully authorized and granted an authorization code or access token. |
Log-out URL | <url>/saml/SingleLogout | The location where a user is directed once they have signed out of the Application. |
How do I register an SSO application?
The values provided by Kingland are used in the registration of the application.
- Sign in to your Azure Account through the Azure Portal.
- Select Azure Active Directory.
- Select App registrations.
- Select New registration.
- Enter the Name of the application.
- Select a supported account type to who can use the application.
- Select Web for the type of application you want to create.
- Enter the Reply URI provided by Kingland.
What information do I need to provide?
The client provides the following data elements to ensure successful setup of SAML SSO integration with EM.
Value | Description |
|---|---|
Directory (tenant) ID | This is the Tenant ID assigned to the application in Azure AD. |
Application (client) ID | This is the Client ID assigned to the application in Azure AD. |
Certificate File | Upload the certificate file to be used to authenticate the application into Azure AD. |
Client Secret | This is the Client Secret configured for the application in Azure AD, if used. |
Where do I get the tenant ID and client ID values?
The information necessary to configure SAML SSO integration with EM is generated when the application is registered in the client Azure Account.
- Sign in to your Azure Account through the Azure Portal.
- Select Azure Active Directory option.
- From App registrations in Azure AD, select the desired application.
- Copy the Application (client) ID and the Directory (tenant) ID values and keep them for setup purposes.
How do I configure authentication?
There are two options available for authentication: 1) certificate-based authentication and 2) password-based authentication (application secret). The recommended method is using a certificate but an application secret may also be created. The certificate may be an existing certificate to be used for the application or a new certificate may be generated in Azure AD.
Upload an existing certificate
- Select Azure Active Directory.
- From App registrations in Azure AD, select the desired application.
- Select Certificates & secrets.
- Select Certificates > Upload certificate and select the applicable certificate.
- Select Add.
- After registering the certificate with the application in the application registration portal, enable the client application code to use the certificate.
Create an application (client) secret
- Select Azure Active Directory.
- From App registrations in Azure AD, select your application.
- Select Certificates & secrets.
- Select Client secrets -> New client secret.
- Enter the description of the new client secret and set a duration.
- Click Add to save the client secret.
- The value of the client secret is displayed after it is created. Be sure to copy the value of the client secret (key) because it cannot be retrieved later.
Where do I obtain the generated certificate information?
As part of registering an application for SAML-based Single Sign-On, Azure AD generates a certificate that is valid for three years unless an existing certificate is uploaded.
- Select the Single sign-on option in the left menu.
- The Single Sign-On with SAML Preview page is presented.
- Click the applicable Download link provided in the SAML Signing Certificate section based on the certificate type desired. The following types are available:
- Base64 - this is formatted as base 64-encoded text file.
- Raw - this is formatted as a binary file.
- Federation Metadata XML - this option may be available based on the application and is formatted as an XML file.