Skip to main content
All CollectionsIntegrationEntra ID
Set-up instructions SSO with Azure AD/ Entra ID
Set-up instructions SSO with Azure AD/ Entra ID
Klaxoon. avatar
Written by Klaxoon.
Updated yesterday

Single sign-on (SSO) allows users to log in to Klaxoon using their Microsoft Entra ID. Here's a detailed guide to setting up SSO.

Prerequisites

  • Microsoft Entra ID administrator account with sufficient roles (Application Administrator, Cloud Application Administrator or Owner)

  • The single sign-on option must be enabled in your Klaxoon subscription

  • A configuration session will be scheduled with Klaxoon technical teams

Configuration

1. Add Klaxoon to Microsoft Entra ID

  1. Log in to the Microsoft Azure portal with an administrator account.

  2. Go to Identity>Applications>Enterprise applications>New application

  3. Search for Klaxoon SAML in the application gallery, then click on Create to create the application.

  4. Select Configure single sign-on.

2. Configure single sign-on (SSO)

  1. Select SAML as authentication method.

  2. Complete the basic SAML configuration:

    • Identifier (Entity ID): Enter the specific URL provided by Klaxoon.

    • Reply URL (Consumer Assertion Service URL): Copy the URL provided by Klaxoon.

  3. Attributes to be included in the SAML callback frame :

    • Last name (“familyName”)

    • First name (“givenName”)

    • Email (“emailAddress”)

    NameID format:

    • Persistent

  4. In the SAML signature certificate section, search for XML federation metadata and select Download to download the certificate and save it on your computer.

3. Assign users or groups

  1. In Microsoft Entra, go to Identity>Users>All users.

  2. Click on Add user/group, then select the users or groups you wish to access Klaxoon.

4. Configuring and testing settings

A configuration session should be scheduled with Klaxoon technical staff. You will need to transmit the metadata file downloaded earlier (see point 2.3). Authentication tests will then be carried out (pre-production and/or production phase). At the end of these tests, SSO will be functional.

If you'd like to find out more about SSO, take a look at the resources available at this link.

Did this answer your question?