This guide describes the setup of Single Sign-On (SSO) with SAML 2.0 between Microsoft Entra ID and Acubiz.
Contents of this article:
- 1. Prerequisites
- 2. Step-by-step configuration
- 3. Submitting metadata to Acubiz
- 4. Testing the SSO connection
1. Prerequisites
To complete the setup, you need the following:
- License: Microsoft Entra ID P1 or P2.
-
Permissions: One of the following roles in Entra ID:
- Global Administrator
- Cloud Application Administrator
- Application Administrator
- Ownership of the relevant Service Principal.
2. Step-by-step configuration
Step 1: Create application in Entra ID
- Log in to the Microsoft Entra admin center.
- Navigate to Enterprise Applications > New application > Create your own application (Non-gallery).
- Name the application Acubiz.
Step 2: Configure SAML-based SSO
- Open the created Acubiz application and select Single sign-on > SAML.
- Import metadata (optional): Use the following URL for automatic filling: https://auth.acubiz.com/federationmetadata/2007-06/federationmetadata.xml
-
Basic SAML Configuration (Fill in manually if metadata is not imported):
- Identifier (Entity ID): https://auth.acubiz.com
- Reply URL (Assertion Consumer Service URL): https://auth.acubiz.com/adfs/ls/
-
Sign on URL:
https://[COMPANYID].acubiz.com
(Note: The exact Sign-on URL must be confirmed by Acubiz).
-
User Attributes & Claims:
-
Unique User Identifier (Name ID):
user.mail(oruser.userprincipalname, if this contains the user's email address). - Other fields can generally be left with default values.
-
Unique User Identifier (Name ID):
Step 3: User and group assignment
Remember to assign relevant users or groups access to the application under Users and groups. Most organizations select the group "All Users".
3. Submitting metadata to Acubiz
Once the configuration in Entra ID is complete, the following information must be sent to your Acubiz consultant:
-
App Federation Metadata URL: Copy the link from the SAML Certificates section in Entra ID.
- Domain list: A complete overview of all email domains used by users in Acubiz.
⚠️ Important: Wait for written confirmation from Acubiz that the configuration has been completed on their IdP platform before starting testing.
4. Testing the SSO connection
When confirmation from Acubiz is received, the SSO connection should be tested:
Go to the Single sign-on section under the Acubiz application in Entra ID.
Proceed to Test of SSO connection to Acubiz.
Comments
0 comments
Please sign in to leave a comment.