Getting started (admin setup)
  • 17 Mar 2024
  • 2 Minutes to read
  • Dark
    Light

Getting started (admin setup)

  • Dark
    Light

Article Summary

Before you setup Azure SAML SSO

Setup Single Sign-on with Azure enterprise application

  1. Sign-in to your Azure admin portal
  2. In the left menu bar, click on Microsoft Entra ID
  3. Click on Enterprise applications in the left menu bar
  4. In the Enterprise applications page, click on New application

image.png

  1. In the Browse Microsoft Entra Gallery page, click on Create your own application

image.png

  1. In the Create your own application,
    1. Enter a name for the application. For example: anchor-saml-sso-app
    2. Select Integrate any other application you don't find in the gallery (Non-gallery)

image.png

  1. Click on Create button
  2. In the newly created application page, select Single sign-on in the left menu bar

image.png

  1. Select SAML in the Select a single sign-on method

image.png

  1. In the Set up Single Sign-On with SAML page, click on Edit icon under Basic SAML configuration

image.png

  1. In the configuration page, click on Add Identifier button

image.png

  1. Now you will need to get the following values from the Anchor admin dashboard.
    1. Identifier (Entity ID)
    2. Reply URL (Assertion Consumer Service URL)
    3. Sign on URL
  2. Sign-in to Anchor admin dashboard
  3. Click on Settings -> Security -> Identity & Provisioning -> SAML SSO

image.png

  1. Click on Add new SAML SSO and select Setup Azure AD SAML SSO

image.png

  1. You will presented with a dialog which contains the following values:

    1. Identifier (Entity ID)
    2. Reply URL (Assertion Consumer Service URL)
    3. Sign on URL
      image.png
  2. Copy the Identifier (Entity ID), Reply URL (Assertion Consumer Service URL), and Sign on URL and paste it in the Azure Basic SAML configuration page like shown below.

image.png

  1. Click on Save button

image.png

  1. Click on the Permissions in the left menu bar and then click on app registration.

image.png

  1. In the API permissions page, click on Add a permission

image.png

  1. Add the following API permissions
    1. Microsoft Graph -> Delegated permissions -> User.Read
    2. Microsoft Graph -> Delegated permissions -> Directory.Read.All
  2. Click on **Grant admin consent **
  1. Go back to Enterprise applications -> find the anchor-saml-sso-app, and then click on Single sign-on.
  2. Download the Base64 certificate, and copy the Login URL
  3. Paste the Login URL in the Sign-in URL field on Anchor dashboard, and upload the Base64 certificate you downloaded to Anchor dashboard.
27. You will see a success dialog box if the setup is successful.

image.png

  1. Click on Close or Logout and verify connection to verify the newly added SAML SSO.

How to verify the newly added SAML SSO?

  1. Make sure that your Azure Microsoft Entra ID primary domain is part of the Anchor primary domains
2. Now sign-out and sign back in to the Anchor admin dashboard 3. When you sign-in, you will be provided with 2 options: 1. Continue with Email 2. Continue with SSO 4. Choose **Continue with SSO** to sign-in with your newly added Azure SAML SSO
5. If sign-in is successful you will be see the home page of admin dashboard.

Was this article helpful?

Changing your password will log you out immediately. Use the new password to log back in.
First name must have atleast 2 characters. Numbers and special characters are not allowed.
Last name must have atleast 1 characters. Numbers and special characters are not allowed.
Enter a valid email
Enter a valid password
Your profile has been successfully updated.