Skip to main content

Single sign-on

In order to set up single sign-on (SSO), the previously created enterprise application needs to be updated.

Prerequisites (provided by Datafisher):

  1. Metadata URL / Identifier / Entity ID
  2. Reply URL

Results (to be provided to Datafisher):

  1. App Federation Metadata Url

Set up SAML parameters

First,

  1. find the application from the enterprise applications list,
  2. open ManageSingle sign-on,
  3. select SAML as the sign-on method.

img

Next, under Basic SAML Configuration click Edit.

img

Next, click on Add identifier and Add reply URL.

img

Next, enter the provided Metadata URL / Identifier / Entity ID and Reply URL into the relevant fields and click Save. Those values should have been provided to you by Datafisher.

img

The Employee ID claim

Next, under Attributes & Claims click Edit.

img

Next, select Add new claim.

img

Next,

  1. enter employeeId as the Name,
  2. user.employeeid (or whichever attribute that contains the employee ID for your company) as the Source Attribute,
  3. click Save.

img

Metadata URL

Next, under SAML Certificates the App Federation Metadata Url is displayed. It must be sent to Datafisher in order to complete SSO setup on the

The fallback content to display on prerendering
side. The URL does not contain any secret information.

img

Assignment

Finally, signing in via the application should be made available for everyone in the tenant by

  1. going to ManageProperties,
  2. changing Assignment Required to No,
  3. clicking Save.

img

Alternatively, only selected users or user groups could be provided access to the application (not recommended) by going to ManageUsers and groups and configuring the settings as needed.

img

The

The fallback content to display on prerendering
usually only allows access to users that have been pre-created in the system. Thus, it is reasonable to limit the creation of users in the LMS, rather than the permission to log in via
The fallback content to display on prerendering
.

Testing

Once the App Federation Metadata Url has been provided to Datafisher and

The fallback content to display on prerendering
side setup completed, you should try logging in to the
The fallback content to display on prerendering
The fallback content to display on prerendering
.