<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Single Sign-On (SSO) Archives - SecurEnds</title>
	<atom:link href="https://www.securends.com/documentation-category/single-sign-on/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.securends.com/documentation-category/single-sign-on/</link>
	<description>SecurEnds - User Access / Entitlement Reviews, Identity Access Management, Cloud Access Management, Identity Governance, IGA, IAM</description>
	<lastBuildDate>Tue, 29 Apr 2025 15:15:32 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.securends.com/wp-content/uploads/2022/02/cropped-se-favicon-new-32x32.png</url>
	<title>Single Sign-On (SSO) Archives - SecurEnds</title>
	<link>https://www.securends.com/documentation-category/single-sign-on/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Azure SSO</title>
		<link>https://www.securends.com/documentation/azure-sso/</link>
					<comments>https://www.securends.com/documentation/azure-sso/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Fri, 11 Dec 2020 18:00:45 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6156</guid>

					<description><![CDATA[<p>Please note, the following steps walk through an example use case and the information that will need to be saved will be specific to your application. Application Registration using Azure Portal To setup Azure Single Sign-On with SecurEnds and Azure AD, you need to register SecurEnds as an application within the Azure portal. Doing this will create the service principal object in your Azure AD tenant. The information that will need to be gathered and saved throughout the steps below are as follows: Tenant Id Client Secret (Value) Client Id Group Name Notice: Desired group must be associated with the SSO application created How to Associate Azure Group to you SSO App in Azure portal: Navigate to Enterprise Applications and search for the application Click on Application name In the Overview screen, click on Assign users and groups Click on Add user/group Here we can add either the user or the group to an application Step 1: Create Application Login in to https://portal.azure.com Navigate to left navigation menu and select Azure Active Directory Make note of the Tenant ID displayed on the right as this will need to be supplied to the SecurEnds team. After making note, select Enterprise applications Select New application. Be sure you have appropriate access. Admin permission is needed to create new application. Select Non&#8211;gallery application Give an application name and select Add After creating an application, you will be automatically navigated to the application overview page Make note of the Application ID and Object ID displayed on the screen as these will need to be supplied to the SecurEnds team After making note, select Single sign-on on the left navigation menu Select Linked as the single sign-on method Provide the Sign on URL and select Save Navigate to home page &#62; select Azure active directory &#62; then select App registrations Select the application just created Select Certificates and secrets Select New client secret Add a Description and select a Expires timeframe. Once complete select Add The Client Secret will be displayed when these settings are saved and compulsory, copy the key to the clipboard, once you leave the page the key will not be visible Make note of the Client Secret (Value) displayed on the screen as this will need to be supplied to the SecurEnds team Step 2: Azure Permissions After registering SecurEnds as an application within the Azure portal, the next step is to make sure the application has the correct API permissions to access data within Microsoft Graph. To do this the user or administrator must grant the correct permissions via a consent process. Select the Authentication link on the left navigation menu and select Add a platform Select Web as the configure platform under web applications Select &#8220;Add a platform&#8221; and input Redirect URL as below: https://companyname.securends.com/login/oauth2/code/azure Configure No need to add Logout URL since we are using REST API for logout Under Logout URL in Implicit Grant, ID token checkbox should be enabled Select API permissions on the left navigation menu and select Add a permission Select Microsoft Graph under Commonly used MicrosoftAPIs Under Microsoft Graph give the following Delegated Permissions. Totaling 4 permissions in all. Delegated permissions: Email Openid Profile Directory Search for Directory Permissions and Select Directory.AccessAsUser.All permission. Select email, openid and profile permissions as shown below Select Add permissions and then select Grant admin consent for ******” Select Yes After selecting required permissions check the status for granted/not granted Admin will get an option to grant those permissions beside &#8220;Add a permission button&#8221; Step 3: Manifest Configuration Select the “Manifest” link on the left navigation menu and update the following: oauth2AllowImplicitFlow value to true Step 4: Users and Groups Creation (Optional) If users and groups HAVE already been created, perform the following actions: Assign the existing Group being used to the Application/SSO Make note of &#8220;Group Name&#8221; as this info needs to be relayed to the SecurEnds team If users and groups HAVE NOT been created, perform the following actions to create them: Create users and groups (If already created then ignore this step) Navigate to Azure Active Directory and select Users Select New User and add the appropriate details Navigate to Azure Active Directory and select Groups Select New Group and add the appropriate users to that group This group contains a list of Active Directory groups to use for authorization Make note of this Group Name as it will need to be supplied to the SecurEnds team Step 5: Configuration Settings Once the steps above have been completed then you can provide SecurEnds the following information that was saved based on the directions from each step Tenant Id Contains your Active Directory&#8217;s Directory ID from earlier Client Id Contains the Application ID from your app registration that you completed earlier Client Secret Contains the Value from your app registration key that you completed earlier Group Name Contains a list of Active Directory groups to use for authorization Step 6: Update Azure Claim Token Required if your company utilizes two logins like UPN (UserPrincipalName) and email. Please go through the below steps to update Azure email claim token. Select the “App registration” link on the left navigation menu. Go to All Applications tab and click on the application for which looking to update an email token. Example : securends-sharepoint as shown in the below screen. Once you have clicked on the Selected application the screen will redirect to the below. Select Token Configuration link on the left navigation menu. Click on Add optional claim, a new screen appears on the left side to Add optional claim. Select Token type as ID and Claim as email. Click on Add button. Successfully, email claim token is updated.</p>
<p>The post <a href="https://www.securends.com/documentation/azure-sso/">Azure SSO</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Please note, the following steps walk through an example use case and the information that will need to be saved will be specific to your application.</p>



<h5 class="wp-block-heading" id="block-7e97c91d-f23e-497d-becd-358905cd71c2"><strong><span class="has-inline-color has-very-dark-gray-color">Application Registration using Azure Portal</span></strong></h5>



<p>To setup Azure Single Sign-On with SecurEnds and Azure AD, you need to register SecurEnds as an application within the Azure portal. Doing this will create the service principal object in your Azure AD tenant.</p>



<p>The information that will need to be gathered and saved throughout the steps below are as follows:</p>



<ul class="wp-block-list"><li>Tenant Id</li><li>Client Secret (Value)</li><li>Client Id</li><li>Group Name <ul><li><strong>Notice</strong>: Desired group must be associated with the SSO application created</li></ul></li></ul>



<ul class="wp-block-list"><li>How to Associate Azure Group to you SSO App in Azure portal:<ul><li>Navigate to <strong>Enterprise Applications </strong>and search for the application</li><li>Click on Application name</li><li>In the Overview screen, click on <strong>Assign users and groups</strong></li><li>Click on <strong>Add user/group</strong></li><li>Here we can add either the user or the group to an application</li></ul></li></ul>



<h5 class="wp-block-heading" id="block-27ee0a03-7075-4efd-9da1-20a1dfa2af7d"><strong><span class="has-inline-color has-very-dark-gray-color">Step 1: Create Application</span></strong></h5>



<ul class="wp-block-list"><li>Login in to <a href="https://portal.azure.com/">https://portal.azure.com</a></li><li>Navigate to left navigation menu and select <strong>Azure Active Directory</strong></li></ul>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="568" height="363" src="https://www.securends.com/wp-content/uploads/2021/09/image-80.png" alt="" class="wp-image-10000" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-80.png 568w, https://www.securends.com/wp-content/uploads/2021/09/image-80-300x192.png 300w" sizes="(max-width: 568px) 100vw, 568px" /></figure>



<ul class="wp-block-list"><li>Make note of the <strong>Tenant ID</strong> displayed on the right as this will need to be supplied to the SecurEnds team. After making note, select <strong>Enterprise applications</strong></li></ul>



<figure class="wp-block-image size-full"><img decoding="async" width="585" height="347" src="https://www.securends.com/wp-content/uploads/2021/09/image-82.png" alt="" class="wp-image-10001" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-82.png 585w, https://www.securends.com/wp-content/uploads/2021/09/image-82-300x178.png 300w" sizes="(max-width: 585px) 100vw, 585px" /></figure>



<ul class="wp-block-list"><li>Select <strong>New application</strong>. Be sure you have appropriate access. Admin permission is needed to create new application.</li></ul>



<figure class="wp-block-image size-full"><img decoding="async" width="550" height="177" src="https://www.securends.com/wp-content/uploads/2021/09/image-84.png" alt="" class="wp-image-10002" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-84.png 550w, https://www.securends.com/wp-content/uploads/2021/09/image-84-300x97.png 300w" sizes="(max-width: 550px) 100vw, 550px" /></figure>



<p>Select <strong>Non</strong>&#8211;<strong>gallery application</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="557" height="265" src="https://www.securends.com/wp-content/uploads/2021/09/image-85.png" alt="" class="wp-image-10003" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-85.png 557w, https://www.securends.com/wp-content/uploads/2021/09/image-85-300x143.png 300w" sizes="(max-width: 557px) 100vw, 557px" /></figure>



<ul class="wp-block-list"><li>Give an application name and select <strong>Add</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="547" height="261" src="https://www.securends.com/wp-content/uploads/2021/09/image-86.png" alt="" class="wp-image-10005" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-86.png 547w, https://www.securends.com/wp-content/uploads/2021/09/image-86-300x143.png 300w" sizes="(max-width: 547px) 100vw, 547px" /></figure>



<ul class="wp-block-list"><li>After creating an application, you will be automatically navigated to the application overview page<ul><li>Make note of the <strong>Application ID</strong> and <strong>Object ID</strong> displayed on the screen as these will need to be supplied to the SecurEnds team</li><li>After making note, select <strong>Single sign-on</strong> on the left navigation menu</li></ul></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="551" height="267" src="https://www.securends.com/wp-content/uploads/2021/09/image-87.png" alt="" class="wp-image-10006" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-87.png 551w, https://www.securends.com/wp-content/uploads/2021/09/image-87-300x145.png 300w" sizes="(max-width: 551px) 100vw, 551px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Linked</strong> as the single sign-on method</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="534" height="226" src="https://www.securends.com/wp-content/uploads/2021/09/image-88.png" alt="" class="wp-image-10007" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-88.png 534w, https://www.securends.com/wp-content/uploads/2021/09/image-88-300x127.png 300w" sizes="(max-width: 534px) 100vw, 534px" /></figure>



<ul class="wp-block-list"><li>Provide the <strong>Sign on URL</strong> and select <strong>Save</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="557" height="175" src="https://www.securends.com/wp-content/uploads/2021/09/image-89.png" alt="" class="wp-image-10008" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-89.png 557w, https://www.securends.com/wp-content/uploads/2021/09/image-89-300x94.png 300w" sizes="(max-width: 557px) 100vw, 557px" /></figure>



<ul class="wp-block-list"><li>Navigate to home page &gt; select <strong>Azure active directory</strong> &gt; then select <strong>App registrations</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="555" height="241" src="https://www.securends.com/wp-content/uploads/2021/09/image-90.png" alt="" class="wp-image-10009" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-90.png 555w, https://www.securends.com/wp-content/uploads/2021/09/image-90-300x130.png 300w" sizes="(max-width: 555px) 100vw, 555px" /></figure>



<ul class="wp-block-list"><li>Select the application just created</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="539" height="249" src="https://www.securends.com/wp-content/uploads/2021/09/image-91.png" alt="" class="wp-image-10010" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-91.png 539w, https://www.securends.com/wp-content/uploads/2021/09/image-91-300x139.png 300w" sizes="(max-width: 539px) 100vw, 539px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Certificates and secrets</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="556" height="240" src="https://www.securends.com/wp-content/uploads/2021/09/image-93.png" alt="" class="wp-image-10011" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-93.png 556w, https://www.securends.com/wp-content/uploads/2021/09/image-93-300x129.png 300w" sizes="(max-width: 556px) 100vw, 556px" /></figure>



<ul class="wp-block-list"><li>Select <strong>New client secret</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="555" height="256" src="https://www.securends.com/wp-content/uploads/2021/09/image-94.png" alt="" class="wp-image-10012" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-94.png 555w, https://www.securends.com/wp-content/uploads/2021/09/image-94-300x138.png 300w" sizes="(max-width: 555px) 100vw, 555px" /></figure>



<ul class="wp-block-list"><li>Add a <strong>Description</strong> and select a <strong>Expires</strong> timeframe. Once complete select <strong>Add</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="545" height="134" src="https://www.securends.com/wp-content/uploads/2021/09/image-95.png" alt="" class="wp-image-10013" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-95.png 545w, https://www.securends.com/wp-content/uploads/2021/09/image-95-300x74.png 300w" sizes="(max-width: 545px) 100vw, 545px" /></figure>



<ul class="wp-block-list"><li>The Client Secret will be displayed when these settings are saved and compulsory, copy the key to the clipboard, once you leave the page the key will not be visible<ul><li>Make note of the <strong>Client Secret</strong> <strong>(Value) </strong>displayed on the screen as this will need to be supplied to the SecurEnds team</li></ul></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="516" height="122" src="https://www.securends.com/wp-content/uploads/2021/09/image-96.png" alt="" class="wp-image-10014" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-96.png 516w, https://www.securends.com/wp-content/uploads/2021/09/image-96-300x71.png 300w" sizes="(max-width: 516px) 100vw, 516px" /></figure>



<h5 class="wp-block-heading" id="block-a07156aa-0a42-4337-b251-ffb87b6204c8"><strong><span class="has-inline-color has-very-dark-gray-color">Step 2: Azure Permissions</span></strong></h5>



<p>After registering SecurEnds as an application within the Azure portal, the next step is to make sure the application has the correct API permissions to access data within Microsoft Graph. To do this the user or administrator must grant the correct permissions via a consent process.</p>



<ul class="wp-block-list"><li>Select the <strong>Authentication</strong> link on the left navigation menu and select <strong>Add a platform</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="534" height="247" src="https://www.securends.com/wp-content/uploads/2021/09/image-97.png" alt="" class="wp-image-10015" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-97.png 534w, https://www.securends.com/wp-content/uploads/2021/09/image-97-300x139.png 300w" sizes="(max-width: 534px) 100vw, 534px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Web</strong> as the configure platform under web applications</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="562" height="225" src="https://www.securends.com/wp-content/uploads/2021/09/image-98.png" alt="" class="wp-image-10016" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-98.png 562w, https://www.securends.com/wp-content/uploads/2021/09/image-98-300x120.png 300w" sizes="(max-width: 562px) 100vw, 562px" /></figure>



<ul class="wp-block-list"><li>Select &#8220;Add a platform&#8221; and input Redirect URL as below:</li><li>https://companyname.securends.com/login/oauth2/code/azure</li><li><strong>Configure</strong></li><li>No need to add Logout URL since we are using REST API for logout</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="557" height="257" src="https://www.securends.com/wp-content/uploads/2021/09/image-99.png" alt="" class="wp-image-10017" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-99.png 557w, https://www.securends.com/wp-content/uploads/2021/09/image-99-300x138.png 300w" sizes="(max-width: 557px) 100vw, 557px" /></figure>



<p>Under Logout URL in <strong>Implicit Grant</strong>, <strong>ID token</strong> checkbox should be enabled</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="899" height="564" src="https://www.securends.com/wp-content/uploads/2022/05/doc-id-token.png" alt="" class="wp-image-13388" srcset="https://www.securends.com/wp-content/uploads/2022/05/doc-id-token.png 899w, https://www.securends.com/wp-content/uploads/2022/05/doc-id-token-300x188.png 300w, https://www.securends.com/wp-content/uploads/2022/05/doc-id-token-768x482.png 768w" sizes="(max-width: 899px) 100vw, 899px" /></figure>



<ul class="wp-block-list"><li>Select <strong>API permissions</strong> on the left navigation menu and select <strong>Add a permission</strong></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="544" height="227" src="https://www.securends.com/wp-content/uploads/2021/09/image-100.png" alt="" class="wp-image-10018" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-100.png 544w, https://www.securends.com/wp-content/uploads/2021/09/image-100-300x125.png 300w" sizes="(max-width: 544px) 100vw, 544px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Microsoft Graph</strong> under Commonly used MicrosoftAPIs</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="560" height="261" src="https://www.securends.com/wp-content/uploads/2021/09/image-101.png" alt="" class="wp-image-10019" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-101.png 560w, https://www.securends.com/wp-content/uploads/2021/09/image-101-300x140.png 300w" sizes="(max-width: 560px) 100vw, 560px" /></figure>



<ul class="wp-block-list"><li>Under <strong>Microsoft Graph</strong> give the following <strong>Delegated</strong> Permissions. Totaling 4 permissions in all.</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="553" height="259" src="https://www.securends.com/wp-content/uploads/2021/09/image-102.png" alt="" class="wp-image-10020" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-102.png 553w, https://www.securends.com/wp-content/uploads/2021/09/image-102-300x141.png 300w" sizes="(max-width: 553px) 100vw, 553px" /></figure>



<ul class="wp-block-list"><li>Delegated permissions:<ul><li>Email</li></ul><ul><li>Openid</li><li>Profile</li><li>Directory</li></ul></li><li>Search for <strong>Directory</strong> Permissions and Select <strong>Directory.AccessAsUser.All</strong> permission.</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="536" height="235" src="https://www.securends.com/wp-content/uploads/2021/09/image-104.png" alt="" class="wp-image-10021" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-104.png 536w, https://www.securends.com/wp-content/uploads/2021/09/image-104-300x132.png 300w" sizes="(max-width: 536px) 100vw, 536px" /></figure>



<ul class="wp-block-list"><li>Select <strong>email, openid and profile </strong>permissions as shown below</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="474" height="378" src="https://www.securends.com/wp-content/uploads/2021/09/image-105.png" alt="" class="wp-image-10022" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-105.png 474w, https://www.securends.com/wp-content/uploads/2021/09/image-105-300x239.png 300w" sizes="(max-width: 474px) 100vw, 474px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Add permissions</strong> and then select <strong>Grant admin consent for ******</strong>”</li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="553" height="233" src="https://www.securends.com/wp-content/uploads/2021/09/image-106.png" alt="" class="wp-image-10023" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-106.png 553w, https://www.securends.com/wp-content/uploads/2021/09/image-106-300x126.png 300w" sizes="(max-width: 553px) 100vw, 553px" /></figure>



<ul class="wp-block-list"><li>Select <strong>Yes</strong></li></ul>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/09/image-107.png" alt="" class="wp-image-10024" width="654" height="85" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-107.png 557w, https://www.securends.com/wp-content/uploads/2021/09/image-107-300x38.png 300w" sizes="(max-width: 654px) 100vw, 654px" /></figure>



<ul class="wp-block-list"><li>After selecting required permissions check the status for granted/not granted<ul><li>Admin will get an option to grant those permissions beside &#8220;Add a permission button&#8221;</li></ul></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1024" height="376" src="https://www.securends.com/wp-content/uploads/2022/05/doc-api-permission.png" alt="" class="wp-image-13405" srcset="https://www.securends.com/wp-content/uploads/2022/05/doc-api-permission.png 1024w, https://www.securends.com/wp-content/uploads/2022/05/doc-api-permission-300x110.png 300w, https://www.securends.com/wp-content/uploads/2022/05/doc-api-permission-768x282.png 768w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<h5 class="wp-block-heading" id="block-07d3be88-e6da-49a8-a994-6f7ec6103f0d"><strong><span class="has-inline-color has-very-dark-gray-color">Step 3: Manifest Configuration</span></strong></h5>



<ul class="wp-block-list"><li>Select the “Manifest” link on the left navigation menu and update the following:<ul><li>oauth2AllowImplicitFlow value to <strong>true</strong></li></ul></li></ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="544" height="256" src="https://www.securends.com/wp-content/uploads/2021/09/image-109.png" alt="" class="wp-image-10025" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-109.png 544w, https://www.securends.com/wp-content/uploads/2021/09/image-109-300x141.png 300w" sizes="(max-width: 544px) 100vw, 544px" /></figure>



<h5 class="wp-block-heading" id="block-1da896b6-7696-4737-b256-bbd25d9c7e5d"><strong><span class="has-inline-color has-very-dark-gray-color">Step 4: Users and Groups Creation (Optional)</span></strong></h5>



<p>If users and groups <strong>HAVE</strong> already been created, perform the following actions:</p>



<ul class="wp-block-list"><li>Assign the existing <strong>Group</strong> being used to the <strong>Application/SSO</strong></li><li>Make note of &#8220;<strong>Group Name</strong>&#8221; as this info needs to be relayed to the SecurEnds team</li></ul>



<p>If users and groups <strong>HAVE NOT </strong>been created, perform the following actions to create them:</p>



<ul class="wp-block-list"><li>Create users and groups (<strong>If already created then ignore this step</strong>)</li><li>Navigate to Azure Active Directory and select <strong>Users</strong></li></ul>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/09/image-110.png" alt="" class="wp-image-10026" width="590" height="98"/></figure>



<ul class="wp-block-list"><li>Select <strong>New User</strong> and add the appropriate details</li><li>Navigate to Azure Active Directory and select <strong>Groups</strong></li></ul>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://www.securends.com/wp-content/uploads/2021/09/image-111.png" alt="" class="wp-image-10027" width="589" height="104"/></figure>



<ul class="wp-block-list"><li>Select <strong>New Group </strong>and add the appropriate users to that group<ul><li>This group contains a list of Active Directory groups to use for authorization</li><li>Make note of this <strong>Group Name</strong> as it will need to be supplied to the SecurEnds team</li></ul></li></ul>



<h5 class="wp-block-heading" id="block-d8bbcdab-97c3-431a-b26e-41862959c4d8"><strong><span class="has-inline-color has-very-dark-gray-color">Step 5: Configuration Settings</span></strong></h5>



<p>Once the steps above have been completed then you can provide SecurEnds the following information that was saved based on the directions from each step</p>



<ul class="wp-block-list"><li>Tenant Id<ul><li>Contains your Active Directory&#8217;s <strong>Directory ID </strong>from earlier</li></ul></li><li>Client Id<ul><li>Contains the <strong>Application ID </strong>from your app registration that you completed earlier</li></ul></li><li>Client Secret<ul><li>Contains the <strong>Value </strong>from your app registration key that you completed earlier</li></ul></li><li>Group Name<ul><li>Contains a list of Active Directory groups to use for authorization</li></ul></li></ul>



<h5 class="wp-block-heading" id="block-d8bbcdab-97c3-431a-b26e-41862959c4d8"><strong><span class="has-inline-color has-very-dark-gray-color">Step 6: Update Azure Claim Token</span></strong></h5>



<p>Required if your company utilizes two logins like UPN (<strong>UserPrincipalName</strong>) and email.  Please go through the below steps to update Azure email claim token.</p>



<ul class="wp-block-list" type="1"><li>Select the “<strong>App registration</strong>” link on the left navigation menu.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="633" height="364" src="https://www.securends.com/wp-content/uploads/2021/09/image-5.png" alt="" class="wp-image-9772" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-5.png 633w, https://www.securends.com/wp-content/uploads/2021/09/image-5-300x173.png 300w" sizes="(max-width: 633px) 100vw, 633px" /></figure>



<ul class="wp-block-list"><li>Go to <strong>All Applications</strong> tab and click on the application for which looking to update an email token.<ul><li>Example : securends-sharepoint as shown in the below screen.</li></ul></li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="645" height="244" src="https://www.securends.com/wp-content/uploads/2021/09/image-6.png" alt="" class="wp-image-9773" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-6.png 645w, https://www.securends.com/wp-content/uploads/2021/09/image-6-300x113.png 300w" sizes="(max-width: 645px) 100vw, 645px" /></figure>



<ul class="wp-block-list" type="1"><li>Once you have clicked on the Selected application the screen will redirect to the below.</li><li>Select <strong>Token Configuration</strong> link on the left navigation menu.</li><li>Click on <strong>Add optional claim, </strong>a new screen appears on the left side to Add optional claim.</li><li>Select <strong>Token type</strong> as <strong>ID </strong>and <strong>Claim </strong>as <strong>email</strong>.</li><li>Click on <strong>Add </strong>button.</li></ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="732" height="320" src="https://www.securends.com/wp-content/uploads/2021/09/image-7.png" alt="" class="wp-image-9774" srcset="https://www.securends.com/wp-content/uploads/2021/09/image-7.png 732w, https://www.securends.com/wp-content/uploads/2021/09/image-7-300x131.png 300w" sizes="(max-width: 732px) 100vw, 732px" /></figure>



<p>Successfully, email claim token is updated.</p>
<p>The post <a href="https://www.securends.com/documentation/azure-sso/">Azure SSO</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/azure-sso/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Okta SSO (SAML)</title>
		<link>https://www.securends.com/documentation/okta-sso-saml/</link>
					<comments>https://www.securends.com/documentation/okta-sso-saml/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Wed, 26 Jan 2022 13:28:58 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=11072</guid>

					<description><![CDATA[<p>Step:1 Create an application in okta This app connector provides the SAML values your app needs to communicate with Okta SAML as an identity provider. It also provides a place for you to provide SAML values that SAML requires to communicate with your app as a service&#160;provider. Please click on Create App Integration Please select an option SAML2.0 Please Enter App Name and click on Next button Please Enter Single Sign On URL and Audience URI(SP Entity ID) and Click On Next Button Single sign-on URL &#8211; https://XXX.securends.com/login/saml2/sso/securends Audience URI (SP Entity ID)&#160; &#8211; https://XXX.securends.com/saml2/service-provider-metadata/securends Note: Replace XXX in the URLwith your domain Please Select I’m an Okta customer adding an internal app option click on Finish Button Please share the following Metadata URL with the securends team. Please Click On View Setup Instructions Final Step: Please assign the created application to people/groups.</p>
<p>The post <a href="https://www.securends.com/documentation/okta-sso-saml/">Okta SSO (SAML)</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Step:1 Create an application in okta</strong></p>



<p>This app connector provides the SAML values your app needs to communicate with Okta SAML as an identity provider. It also provides a place for you to provide SAML values that SAML requires to communicate with your app as a service&nbsp;provider.</p>



<ol class="wp-block-list">
<li>Access&nbsp;Okta.</li>



<li>Go to Applications</li>
</ol>



<p><strong>Please click on Create App Integration</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="400" src="https://www.securends.com/wp-content/uploads/2022/01/image-4.png" alt="" class="wp-image-11062" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-4.png 864w, https://www.securends.com/wp-content/uploads/2022/01/image-4-300x139.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-4-768x356.png 768w" sizes="(max-width: 864px) 100vw, 864px" /></figure>



<p><strong>Please select an option SAML2.0</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="849" height="501" src="https://www.securends.com/wp-content/uploads/2022/01/image-5.png" alt="" class="wp-image-11063" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-5.png 849w, https://www.securends.com/wp-content/uploads/2022/01/image-5-300x177.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-5-768x453.png 768w" sizes="(max-width: 849px) 100vw, 849px" /></figure>



<p><strong>Please Enter App Name and click on Next button</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1014" height="585" src="https://www.securends.com/wp-content/uploads/2022/01/image-6.png" alt="" class="wp-image-11064" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-6.png 1014w, https://www.securends.com/wp-content/uploads/2022/01/image-6-300x173.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-6-768x443.png 768w" sizes="(max-width: 1014px) 100vw, 1014px" /></figure>



<p><strong>Please Enter Single Sign On URL and Audience URI(SP Entity ID) and Click On Next Button</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="929" height="321" src="https://www.securends.com/wp-content/uploads/2025/04/image-2.png" alt="" class="wp-image-21660" srcset="https://www.securends.com/wp-content/uploads/2025/04/image-2.png 929w, https://www.securends.com/wp-content/uploads/2025/04/image-2-300x104.png 300w, https://www.securends.com/wp-content/uploads/2025/04/image-2-768x265.png 768w, https://www.securends.com/wp-content/uploads/2025/04/image-2-360x124.png 360w" sizes="(max-width: 929px) 100vw, 929px" /></figure>



<p><strong>Single sign-on URL &#8211; <a href="https://XXX.securends.com/login/saml2/sso/securends">https://XXX.securends.com/login/saml2/sso/securends</a></strong></p>



<p><strong>Audience URI (SP Entity ID)&nbsp; &#8211; <a href="https://qa25.securends.com/saml2/service-provider-metadata/securends">https://XXX.securends.com/saml2/service-provider-metadata/securends</a></strong></p>



<p><strong>Note</strong>: Replace <strong>XXX </strong>in the URLwith your domain</p>



<p><strong>Please Select I’m an Okta customer adding an internal app option</strong></p>



<p><strong>click on Finish Button</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="495" src="https://www.securends.com/wp-content/uploads/2022/01/image-8.png" alt="" class="wp-image-11066" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-8.png 865w, https://www.securends.com/wp-content/uploads/2022/01/image-8-300x172.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-8-768x439.png 768w" sizes="(max-width: 865px) 100vw, 865px" /></figure>



<p><strong>Please share the following Metadata URL with the securends team.</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1283" height="714" src="https://www.securends.com/wp-content/uploads/2025/04/image-3.png" alt="" class="wp-image-21664" srcset="https://www.securends.com/wp-content/uploads/2025/04/image-3.png 1283w, https://www.securends.com/wp-content/uploads/2025/04/image-3-300x167.png 300w, https://www.securends.com/wp-content/uploads/2025/04/image-3-1024x570.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/image-3-768x427.png 768w, https://www.securends.com/wp-content/uploads/2025/04/image-3-360x200.png 360w" sizes="(max-width: 1283px) 100vw, 1283px" /></figure>



<p></p>



<p><strong>Please Click On View Setup Instructions</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="368" src="https://www.securends.com/wp-content/uploads/2022/01/image-11.png" alt="" class="wp-image-11069" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-11.png 863w, https://www.securends.com/wp-content/uploads/2022/01/image-11-300x128.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-11-768x327.png 768w" sizes="(max-width: 863px) 100vw, 863px" /></figure>



<p></p>



<p><strong>Final Step: Please assign the created application to people/groups.<br><br></strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="355" src="https://www.securends.com/wp-content/uploads/2022/01/image-13.png" alt="" class="wp-image-11071" srcset="https://www.securends.com/wp-content/uploads/2022/01/image-13.png 864w, https://www.securends.com/wp-content/uploads/2022/01/image-13-300x123.png 300w, https://www.securends.com/wp-content/uploads/2022/01/image-13-768x316.png 768w" sizes="(max-width: 864px) 100vw, 864px" /></figure>
<p>The post <a href="https://www.securends.com/documentation/okta-sso-saml/">Okta SSO (SAML)</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/okta-sso-saml/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Okta SSO (OIDC)</title>
		<link>https://www.securends.com/documentation/okta-sso/</link>
					<comments>https://www.securends.com/documentation/okta-sso/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Fri, 11 Dec 2020 18:01:02 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=6158</guid>

					<description><![CDATA[<p>Supported Features SecurEnds application supports the following OIDC feature:. Service Provider (SP)-Initiated Authentication (SSO) Flow Okta SSO Integration Setup Instructions 1. Create an app integration after log in to Okta 2. Choose OIDC-OpenID Connect as Sign-in method and Web Application as Application type, then click Next. 3. Please fill out the form and give your app integration a descriptive name (e.g., SecurEnds). Follow the steps below: 4. Click General tab, Click Edit under General Settings, Please make the following changes as shown in the screen shot and click Save 5. Once the application created, Go to the application , Select the General tab, copy the Client ID and Client secret values. These values will need to be provided to your SecurEnds Implementation Consultant to be configured within your organizations SecurEnds instance The following information will need to be provided with SecurEnds team to enable Okta SSO 6. Assign Users/Groups Test Single Sign-On Notes:Users can access SecurEnds application using OIDC features in the following ways:</p>
<p>The post <a href="https://www.securends.com/documentation/okta-sso/">Okta SSO (OIDC)</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h5 class="wp-block-heading" id="h-supported-features"><strong><span class="has-inline-color has-very-dark-gray-color">Supported Features</span></strong></h5>



<p><strong>SecurEnds application supports the following OIDC feature:<br></strong>. Service Provider (SP)-Initiated Authentication (SSO) Flow</p>



<p><a><strong>Okta SSO Integration Setup Instructions</strong></a><br>   1. Create an app integration after log in to Okta</p>



<ol class="wp-block-list"></ol>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="957" height="523" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-1.png" alt="" class="wp-image-21670" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-1.png 957w, https://www.securends.com/wp-content/uploads/2025/04/oidc-1-300x164.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-1-768x420.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-1-360x197.png 360w" sizes="(max-width: 957px) 100vw, 957px" /></figure>



<p><strong>2. Choose OIDC-OpenID Connect as Sign-in method and Web Application as Application type, then click Next.</strong></p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="980" height="519" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-2.png" alt="" class="wp-image-21671" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-2.png 980w, https://www.securends.com/wp-content/uploads/2025/04/oidc-2-300x159.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-2-768x407.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-2-360x191.png 360w" sizes="(max-width: 980px) 100vw, 980px" /></figure>



<p><strong>3. Please fill out the form and give your app integration a descriptive name (e.g., SecurEnds). Follow the steps below:</strong></p>



<ol class="wp-block-list">
<li><strong>Sign-in redirect URIs</strong>:  e.g., <a href="https://XXX.securends.com/login/oauth2/code/okta">https://XXX.securends.com/login/oauth2/code/okta</a> (Replace <strong>XXX </strong>with your domain)</li>



<li><strong>Sign-out redirect URIs</strong>: e.g., https://XXX.securends.com(Replace <strong>XXX </strong>with your domain)</li>



<li><strong>Skip group assignment for now</strong></li>



<li>Others remain default settings</li>



<li>Then click <strong>Save</strong></li>
</ol>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="762" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-3-1024x762.png" alt="" class="wp-image-21672" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-3-1024x762.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/oidc-3-300x223.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-3-768x572.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-3-360x268.png 360w, https://www.securends.com/wp-content/uploads/2025/04/oidc-3.png 1057w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>4. Click General tab, Click Edit under General Settings, Please make the following changes as shown in the screen shot and click Save</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="507" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-4-1024x507.png" alt="" class="wp-image-21673" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-4-1024x507.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/oidc-4-300x148.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-4-768x380.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-4-360x178.png 360w, https://www.securends.com/wp-content/uploads/2025/04/oidc-4.png 1057w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>5. Once the application created, Go to the application , Select the General tab, copy the Client ID and Client secret values. These values will need to be provided to your SecurEnds Implementation Consultant to be configured within your organizations SecurEnds instance</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="563" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-5-1024x563.png" alt="" class="wp-image-21674" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-5-1024x563.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/oidc-5-300x165.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-5-768x422.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-5-360x198.png 360w, https://www.securends.com/wp-content/uploads/2025/04/oidc-5.png 1119w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>The following information will need to be provided with SecurEnds team to enable Okta SSO</strong></p>



<ul class="wp-block-list">
<li>Client ID</li>



<li>Client Secret</li>



<li>Issuer  Ex: <a href="https://dev-56658065.okta.com">https://dev-880769.okta.com</a> (In the upper-right corner, locate the organization URL, which takes the form of https://your_domain.okta.com.)</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="632" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-6-1024x632.png" alt="" class="wp-image-21675" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-6-1024x632.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/oidc-6-300x185.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-6-768x474.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-6-360x222.png 360w, https://www.securends.com/wp-content/uploads/2025/04/oidc-6.png 1141w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p></p>



<p><strong>6. Assign Users/Groups</strong></p>



<ul class="wp-block-list">
<li>Choose application the one you created</li>



<li>Select the Assignments tab</li>



<li>Select Assign and then select either Assign to People or Assign to Groups</li>



<li>Enter the appropriate users or groups that you wish to enable Single Sign-On into your application, and then select <strong>Assign </strong>for each</li>



<li>For any users that you added, verify the user-specific attributes, and then select Save and Go Back</li>



<li>Select Done</li>
</ul>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="526" src="https://www.securends.com/wp-content/uploads/2025/04/oidc-7-1024x526.png" alt="" class="wp-image-21676" srcset="https://www.securends.com/wp-content/uploads/2025/04/oidc-7-1024x526.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/oidc-7-300x154.png 300w, https://www.securends.com/wp-content/uploads/2025/04/oidc-7-768x394.png 768w, https://www.securends.com/wp-content/uploads/2025/04/oidc-7-360x185.png 360w, https://www.securends.com/wp-content/uploads/2025/04/oidc-7.png 1186w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p></p>



<p><a><strong>Test Single Sign-On</strong></a></p>



<ol class="wp-block-list">
<li>Sign out of your administrator account within your development org by selecting “<strong>Sign</strong> <strong>out</strong>” in the upper-right corner of the Admin Console</li>



<li>Sign in to the Okta End-User Dashboard as the normal user who was assigned the SecurEnds integration</li>



<li>In your dashboard, select the Okta tile for the integration and confirm that the user is signed into SecurEnds application</li>
</ol>



<p><a><strong>Notes</strong></a>:<br>Users can access SecurEnds application using OIDC features in the following ways:</p>



<ol class="wp-block-list">
<li><strong>Customer can login to their okta org url</strong>
<ul class="wp-block-list">
<li>After authentication, customer can click on the SecurEnds App available in the dashboard and will be redirected to the SecurEnds application</li>
</ul>
</li>



<li><strong>Access SecurEnds instance url directly</strong>
<ul class="wp-block-list">
<li>Customer will be redirected to their okta org for authentication and after authentication customer will be redirected back to SecurEnds application</li>
</ul>
</li>
</ol>



<p></p>
<p>The post <a href="https://www.securends.com/documentation/okta-sso/">Okta SSO (OIDC)</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/okta-sso/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>OneLogin SSO</title>
		<link>https://www.securends.com/documentation/onelogin-sso/</link>
					<comments>https://www.securends.com/documentation/onelogin-sso/#respond</comments>
		
		<dc:creator><![CDATA[Bathool Mohd]]></dc:creator>
		<pubDate>Wed, 18 Aug 2021 14:15:47 +0000</pubDate>
				<guid isPermaLink="false">https://www.securends.com/?post_type=docs&#038;p=9611</guid>

					<description><![CDATA[<p>Step:1 Create an app connector in OneLogin Use the SAML Test Connector (Advanced) connector to build an application connector for your app. This app connector provides the SAML values your app needs to communicate with OneLogin as an identity provider. It also provides a place for you to provide SAML values that OneLogin requires to communicate with your app as a service&#160;provider. Side Navigation Bar Details Info : Configuration: The screenshot below represents sample data to setup the SAML OneLogin SSO. Audience (EntityID) &#8211; https://XXX.securends.com/saml2/service-provider-metadata/securends Recipient &#8211; https://XXX.securends.com/login/saml2/sso/securends ACS (Consumer) URL Validator* &#8211; https:\/\/XXX.securends.com\/login/saml2/sso/securends ACS (Consumer) URL* &#8211; https://XXX.securends.com/login/saml2/sso/securends Login URL &#8211; https://XXX.securends.com/login/saml2/sso/securends Note: Replace XXX in the URLwith your domain The data will be transferred between the Service Provider(SecurEnds) to the Identity Provider(OneLogin) in a secure manner. A public key needs to be added in the SAML Encryption field. Parameters: SSO: Select &#8220;SHA-256&#8221; for SAML Signature Algorithm. Copy the Issuer URL and forward to the SecurEnds team. Add Users: Go to&#160;Users &#62; Users&#160;and click the&#160;New User&#160;button to open the&#160;User Info&#160;page On the&#160;User Info&#160;page, verify that the user is activated (Green). Enter the user&#8217;s name and email address, along with any other personal information you want to include. (Note: The user will receive the verification email and should activate the account). Click the SAVE USER button. Assign User to App Add Role</p>
<p>The post <a href="https://www.securends.com/documentation/onelogin-sso/">OneLogin SSO</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Step:1 Create an app connector in OneLogin</strong></p>



<p>Use the <a href="https://onelogin.service-now.com/support?id=kb_article&amp;sys_id=c89fefdadb2310503de43e043996195a"><span class="has-inline-color has-vivid-cyan-blue-color">SAML Test Connector (Advanced)</span></a> connector to build an application connector for your app. </p>



<p>This app connector provides the SAML values your app needs to communicate with OneLogin as an identity provider. It also provides a place for you to provide SAML values that OneLogin requires to communicate with your app as a service&nbsp;provider.</p>



<ol class="wp-block-list">
<li>Access OneLogin.</li>



<li>Go to Apps > Add Apps.</li>



<li>Search for SAML Test Connector.</li>



<li>Select the SAML Test Connector (Advanced) app.</li>
</ol>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="282" src="https://www.securends.com/wp-content/uploads/2022/04/MicrosoftTeams-image-2-1024x282.png" alt="" class="wp-image-12480" srcset="https://www.securends.com/wp-content/uploads/2022/04/MicrosoftTeams-image-2-1024x282.png 1024w, https://www.securends.com/wp-content/uploads/2022/04/MicrosoftTeams-image-2-300x82.png 300w, https://www.securends.com/wp-content/uploads/2022/04/MicrosoftTeams-image-2-768x211.png 768w, https://www.securends.com/wp-content/uploads/2022/04/MicrosoftTeams-image-2.png 1091w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<ol start="5" class="wp-block-list">
<li>Edit the Display Name, if required. In the case of working with the demo1 app, enter demo1.</li>



<li>Accept the default values and click Save.</li>



<li>Keep the OneLogin app connector UI open for the next task.  Click Save</li>
</ol>



<h5 class="wp-block-heading" id="h-side-navigation-bar-details"><strong><u>Side Navigation Bar Details</u></strong></h5>



<p><strong>Info :</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="705" src="https://www.securends.com/wp-content/uploads/2021/08/1-16-1024x705.png" alt="" class="wp-image-9582" srcset="https://www.securends.com/wp-content/uploads/2021/08/1-16-1024x705.png 1024w, https://www.securends.com/wp-content/uploads/2021/08/1-16-300x206.png 300w, https://www.securends.com/wp-content/uploads/2021/08/1-16-768x528.png 768w, https://www.securends.com/wp-content/uploads/2021/08/1-16-1536x1057.png 1536w, https://www.securends.com/wp-content/uploads/2021/08/1-16.png 1747w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Configuration:</strong></p>



<p>The screenshot below represents sample data to setup the SAML OneLogin SSO.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="332" src="https://www.securends.com/wp-content/uploads/2025/04/image-4-1024x332.png" alt="" class="wp-image-21666" srcset="https://www.securends.com/wp-content/uploads/2025/04/image-4-1024x332.png 1024w, https://www.securends.com/wp-content/uploads/2025/04/image-4-300x97.png 300w, https://www.securends.com/wp-content/uploads/2025/04/image-4-768x249.png 768w, https://www.securends.com/wp-content/uploads/2025/04/image-4-360x117.png 360w, https://www.securends.com/wp-content/uploads/2025/04/image-4.png 1221w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Audience (EntityID) &#8211; <a href="https://XXX.securends.com/saml2/service-provider-metadata/securends">https://XXX.securends.com/saml2/service-provider-metadata/securends</a></strong></p>



<p><strong>Recipient &#8211; <a href="https://XXX.securends.com/login/saml2/sso/securends">https://XXX.securends.com/login/saml2/sso/securends</a></strong></p>



<p><strong>ACS (Consumer) URL Validator* &#8211; https:\/\/XXX.securends.com\/login/saml2/sso/securends</strong></p>



<p><strong>ACS (Consumer) URL* &#8211; <a href="https://XXX.securends.com/login/saml2/sso/securends">https://XXX.securends.com/login/saml2/sso/securends</a></strong></p>



<p><strong>Login URL &#8211; <a href="https://XXX.securends.com/login/saml2/sso/securends">https://XXX.securends.com/login/saml2/sso/securends</a></strong></p>



<p><strong>Note: </strong>Replace XXX in the URLwith your domain</p>



<p>The data will be transferred between the Service Provider(SecurEnds) to the Identity Provider(OneLogin) in a secure manner.  A public key needs to be added in the SAML Encryption field. </p>



<p><strong>Parameters:</strong></p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="282" src="https://www.securends.com/wp-content/uploads/2021/08/1-18-1024x282.png" alt="" class="wp-image-9584" srcset="https://www.securends.com/wp-content/uploads/2021/08/1-18-1024x282.png 1024w, https://www.securends.com/wp-content/uploads/2021/08/1-18-300x83.png 300w, https://www.securends.com/wp-content/uploads/2021/08/1-18-768x212.png 768w, https://www.securends.com/wp-content/uploads/2021/08/1-18-1536x423.png 1536w, https://www.securends.com/wp-content/uploads/2021/08/1-18.png 1906w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>SSO:</strong></p>



<p>Select &#8220;SHA-256&#8221; for SAML Signature Algorithm.  Copy the Issuer URL and forward to the SecurEnds team.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="712" src="https://www.securends.com/wp-content/uploads/2021/08/1-19-1024x712.png" alt="" class="wp-image-9585" srcset="https://www.securends.com/wp-content/uploads/2021/08/1-19-1024x712.png 1024w, https://www.securends.com/wp-content/uploads/2021/08/1-19-300x208.png 300w, https://www.securends.com/wp-content/uploads/2021/08/1-19-768x534.png 768w, https://www.securends.com/wp-content/uploads/2021/08/1-19-1536x1067.png 1536w, https://www.securends.com/wp-content/uploads/2021/08/1-19.png 1744w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p><strong>Add Users:</strong></p>



<p>Go to&nbsp;Users &gt; Users&nbsp;and click the&nbsp;New User&nbsp;button to open the&nbsp;User Info&nbsp;page</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="863" height="321" src="https://www.securends.com/wp-content/uploads/2022/02/image.png" alt="" class="wp-image-11175" srcset="https://www.securends.com/wp-content/uploads/2022/02/image.png 863w, https://www.securends.com/wp-content/uploads/2022/02/image-300x112.png 300w, https://www.securends.com/wp-content/uploads/2022/02/image-768x286.png 768w" sizes="(max-width: 863px) 100vw, 863px" /></figure>



<p>On the&nbsp;User Info&nbsp;page, verify that the user is activated (Green). Enter the user&#8217;s name and email address, along with any other personal information you want to include. (<strong>Note: </strong>The user will receive the verification email and should activate the account).  Click the <strong>SAVE USER</strong> button.</p>



<p><strong>Assign User to App</strong></p>



<ul class="wp-block-list">
<li>In OneLogin, click <strong>Users</strong>, and then select each user you want to add.</li>



<li>In the user info page, click <strong>Applications</strong></li>



<li>Click + icon and select the application from drop down and click <strong>Continue</strong>.</li>



<li>Then click <strong>Save</strong>.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="474" src="https://www.securends.com/wp-content/uploads/2022/02/image-1.png" alt="" class="wp-image-11176" srcset="https://www.securends.com/wp-content/uploads/2022/02/image-1.png 865w, https://www.securends.com/wp-content/uploads/2022/02/image-1-300x164.png 300w, https://www.securends.com/wp-content/uploads/2022/02/image-1-768x421.png 768w" sizes="(max-width: 865px) 100vw, 865px" /></figure>



<p><strong>Add Role</strong></p>



<ul class="wp-block-list">
<li>Click <strong>Users</strong> and select <strong>Roles</strong></li>



<li>Enter a name for the new role, click <strong>Save</strong>. (Example: Admin/Finance/ Account. It can be any name you want to provide for the role).</li>



<li>In Roles, open the new Role by clicking the one you created.</li>



<li>Click <strong>Users </strong>(left side navigation)</li>



<li>In <strong>Check existing or add new users to this role</strong>, enter the name(s) of the users to add.</li>



<li>When you have located each user name, click <strong>Check</strong>.</li>



<li>For each user, click <strong>Add to Role</strong>. When you are done, the user(s) are listed in <strong>Users Add Manually</strong>.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="864" height="391" src="https://www.securends.com/wp-content/uploads/2022/02/image-2.png" alt="" class="wp-image-11177" srcset="https://www.securends.com/wp-content/uploads/2022/02/image-2.png 864w, https://www.securends.com/wp-content/uploads/2022/02/image-2-300x136.png 300w, https://www.securends.com/wp-content/uploads/2022/02/image-2-768x348.png 768w" sizes="(max-width: 864px) 100vw, 864px" /></figure>



<ul class="wp-block-list">
<li>Click <strong>Save</strong>. You are returned to the Roles page.</li>



<li>In the Role, click <strong>Applications</strong>.</li>



<li>Click the <strong>Add Apps or +</strong> Icon.</li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="865" height="168" src="https://www.securends.com/wp-content/uploads/2022/02/image-3.png" alt="" class="wp-image-11178" srcset="https://www.securends.com/wp-content/uploads/2022/02/image-3.png 865w, https://www.securends.com/wp-content/uploads/2022/02/image-3-300x58.png 300w, https://www.securends.com/wp-content/uploads/2022/02/image-3-768x149.png 768w" sizes="(max-width: 865px) 100vw, 865px" /></figure>



<p></p>



<p></p>



<p><br><br></p>
<p>The post <a href="https://www.securends.com/documentation/onelogin-sso/">OneLogin SSO</a> appeared first on <a href="https://www.securends.com">SecurEnds</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.securends.com/documentation/onelogin-sso/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
