Please be aware, this feature is only available on v15.5.1 and above. You can find information about upgrading/patching here.
Pre-Requisites:
As of version 16.0.0 and later, you must setup Graph AD Sync BEFORE you setup your Single Sign In (SSO) configuration.
This requires you have an "Enterprise Application" setup with your secret key in Azure and all your users and groups that you want to have access to your Intranet are already setup inside.
Setup Single Sign On
Complete the following steps to set up Single Sign On using Azure Entra ID
Configure Entra ID
- Login to https://portal.azure.com and click Manage Microsoft Entra ID
- On left side menu click Enterprise Applications
- Click New Application
- Click Create your own application
- Set a Name for application and select the Integrate any other application …
- Click Single Sign-on then Select SAML
- Click the "Edit" Pencil button inside the box labelled "Basic SAML Configuration".
- Set Intranet Home Page address for Identifier and Login Page Address for Replay URL and click Save
Click "Add Identifier" and "Add reply URL" buttons so the form entries appear: - Check the configuration
- Note: Test Sign in will not work before completing all steps
Configure Intranet Application
- Login with a Superadmin account and select Admin Menu
- In Security Tab Click on Authentication Mode
- Check Single Sign-On (SSO) option and Save
- Back to Security Tab and Click on Single Sign On
- In Azure Portal select the application and copy App Federation Metadata Url
- Paste in Metadata XML Url and click Import
- In Azure Portal from Properties copy User access URL
- Paste in Login Url and click Save
- For Mapping Unknown SSO User to new user or existing one Click on Single Sign-On Mapping
- In Azure Portal select the application and copy App Federation Metadata Url (Repeat step 20)
- Paste in Metadata XML Url and click Import
- Fill Name ID Field if you need to map Existing User (Entra ID default value is selected in screenshot)
- Fill Create New User, Person and Employee fields if you need to create New User (Entra ID default values are selected in screenshot)
- Click Save
- New users can add missing personal information by editing their profiles. Which fields users can edit is controlled in Manage Fields from Directory Tab