Configuring SAML using Azure
PART 1: creating your app
1- Go to https://portal.azure.com
2- Go "HOME-> Enterprise Applications -> New Application -> Create your own Application", to create your application. Set a name for it and select Unlisted
data:image/s3,"s3://crabby-images/f22a5/f22a58ca972a3b5089812f00d4ae1e59b4e9d648" alt=""
user must have one of the following roles :
- Global Administrator
- Cloud Application Administrator
- Application Administrator
3- choose create your own application
data:image/s3,"s3://crabby-images/c2768/c2768b94a5ec2288039c414200814fab2358d37c" alt=""
4- give it a name and press create
data:image/s3,"s3://crabby-images/98ee5/98ee56e4570d9c1a55cd7b4a8aa6cf7c53afa433" alt=""
5- assign users or groups that can login to the dmax - press Assign users and groups
data:image/s3,"s3://crabby-images/2133b/2133b476bfb0b20e25afc55b83aae343cd660e05" alt=""
6- after assigining the users/groups , go back to overview and press set up signle sign on
data:image/s3,"s3://crabby-images/b359e/b359e555972ce5b6e8484f9a0cb56cb874b6e269" alt=""
7- select SAML
data:image/s3,"s3://crabby-images/552a8/552a8b89093a8c27683dd33b33f564b27e371ba1" alt=""
8- press edit to the Basic SAML Configuration
data:image/s3,"s3://crabby-images/8db87/8db872ae35f6fdb2577c7fb153d51ea01b5861f7" alt=""
9- configure the Identifier (Entity ID) , this is the external url of your portal for example : https://lab120.cybercloudnetworks.net
10- configure the Reply URL (Assertion Consumer Service URL) it is the external url of your portal + /apv1/ssocallback like :
https://lab120.cybercloudnetworks.net/apiv1/ssocallback
11- press Attributes & Claims to add the group claim
data:image/s3,"s3://crabby-images/35553/3555311a45fdda4a8f7197a8d66b182fdb0586fd" alt=""
You can choose instead of all groups only assign or other to get less groups with the user claim
12- copy and save the login url and download the certificate
data:image/s3,"s3://crabby-images/03229/0322967fb4ca1128dd47050bf140e3c4b90dae91" alt=""
13 open the dmax and go to authenticaion (you can configure frontend for portal safe saml or admin saml for administrator
data:image/s3,"s3://crabby-images/e4bf5/e4bf5674421b276269acea6cd5fcb8b1b8f57ec8" alt=""
14 configure the following :
- Entry Point : is the Login URL of the from microsoft portal that we take before
- Issuer : is the portal url https://lab120.cybercloudnetworks.net
- callbackUrl : is the url plus the callback like https://lab120.cybercloudnetworks.net/apiv1/ssocallback
- base 64 certificate: upload the certificate that you downloaded from microsoft before
data:image/s3,"s3://crabby-images/739bb/739bb79fd91739461cd58e0c05336575edcb8a9d" alt=""
15- go to authentication profile edit the profile where you want to enable saml
data:image/s3,"s3://crabby-images/19eb9/19eb9b2e139f7c73466b0a9b91611ced54517d96" alt=""
16- on SAML enable it and add the groups you want to be allowed - the group id you can take it from azure groups , propierties
data:image/s3,"s3://crabby-images/0efe3/0efe3ddcb0a91c3bbb0ca82ccec4f35b03f29cf4" alt=""
data:image/s3,"s3://crabby-images/d97c4/d97c40c91cba95b9345fc72d49457f52c73c05d7" alt=""
Updated 3 months ago