Azure Active Directory Configuration for SSO

Prev Next

Suggested Reading: Single Sign-On (SSO)

This guide lists the actions you need to complete to configure SSO with Microsoft Azure Active Directory (AD), often called AD-SSO, as your identity provider:

  1. Go to Settings > Inone Settings > Security on your Inone panel.

  1. Click the "Enable SSO" checkbox to enable Single Sign-on. The workplace ID given will be the ID you use to enter the panel when first signing in with SSO. This ID is the same as the panel name.

  2. If you want to enforce all users to enter the panel via SSO, you can check the “Use SSO as default login method” checkbox. Once you check this box, your current users will not be able to use their Insider-specific usernames and passwords.

  3. Log in to your Azure AD app and go to Applications > Enterprise Applications to click the + New application button.

  1. Click the + Create your own application button.

  1. Name your app and choose the option shown below on the pop-up. 

If you have multiple panels and want to assign different user roles to each, you need to create separate applications for each panel. You can name them accordingly.

  1. Go to the “Set up single sign-on” option.

  1. Select SAML as your single sign-on method.

  1. On the following page, click the Edit button next to the Basic SAML Configuration.

  1. Copy the Insider SSO URL from the Insider One panel and paste it into the Reply URL (Assertion Consumer Service URL) on Azure. Copy the Service Provider Entity ID from the Insider One panel and paste it into Identifier (Entity ID).

  1. Leave the Sign on URL (Optional) and Relay State (Optional) options empty.

  2. To enable Single Logout, check the "Enable SLO" box. Then copy the given Insider Single Logout URL and paste it into the Logout URL section on Azure on the same page above.

  1. Click the Save button on Azure to complete this step. 

  2. On the following page, click the Edit button next to Attributes & Claims.

  1. Go to Unique User Identifier (Name ID).

  1. Choose email address for the Name identifier format, and user.mail for the Source attribute.

  1. Go to Manage > Single sign-on on the left menu to download the Federation Metadata XML. You’ll see an XML file downloaded on your computer. 

  1. Go to Settings > Inone Settings > Security on your Inone panel and upload the downloaded XML file. The IDP Issuer, IDP SSO Login URL, and x.509 Public Certificate fields will be populated automatically. 

You can also enter the values manually if you prefer.

  1. If you have enabled Single Logout for Insider One, copy the Logout URL listed in the 4th step in the image below and paste it into the IDP Logout URL field on Insider One.

  1. To test the connection in Azure, assign your user to the newly created app. Click the Users and Groups tab on the left menu. Click the + Add user/group button. 

  1. In the pop-up, select your user and click Assign.

  1. Now test the SSO connection on Insider One. Once you click the Test SSO Connection button, the connection will be tested. If there is an error, you will see the error code next to the button. 

  1. Click the Save button to save the settings. You must pass the SSO connection test to save the settings. 

Congrats! You have successfully set up SSO for your panel users with Azure AD.