SAML Configuration for Azure

To set up an Microsoft Azure application as your Identity Provider to allow SAML authentication:

  1. Log in to the Avanan Administrator Portal:

    1. Go to Security Settings > Settings and click Configure SAML.

      The Configure SAML window appears.

    2. To copy the SAML SSO url, in the SAML SSO URL field, click .

  2. Log in to the Microsoft Azure:

    1. Click Enterprise applications from the left navigation pane.

    2. Click New application.

    3. Select Non-gallery application.

    4. In the Name field, enter a name for the application.

    5. Click Add.

    6. Select Set up single sign on.

    7. Select SAML.

    8. In the Identifier (Entity ID) field, enter a unique string, for example, Avanan.

    9. In the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) fields, paste the url copied in step 1.b.

    10. In the Sign on URL field, enter your Avanan Administrator Portal url.

    11. Click Save.

    12. In the User Attributes & Claims field, click .

    13. From the Source attribute field, select one of these:

      • user.mail

      • user.userprinciplename

      Note - Make sure that user.mail is populated for all relevant users when making your selection, if not, authenticating users becomes impossible.

    14. In the SAML signing certificate section, for Federation Metadata XML, click Download.

  3. Log in to the Avanan Administrator Portal:

    1. Go to Security Settings > Settings and click Configure SAML.

      The Configure SAML window appears.

    2. In the Metadata Source field, select Import a metadata file and upload the Federation Metadata XML file downloaded in step 2.n.

    3. Unselect the Are you running Azure AD checkbox.

    4. In the Identity Provider Entity ID field, enter the enter a unique string entered in step 2.h.

  4. Log in to the Microsoft Azure Portal:

    1. Go to Manage > Users and groups.

    2. Click Add user.

    3. From the Users and groups list, select the user or group you want to grant access.

    4. Click Assign.

    You are now able to login to the Avanan Administrator Portal with SAML.