Difficulty: expert
Content
Table of Contents | ||||
---|---|---|---|---|
|
Learning Objectives
After reading this article, you’ll be able to:
Configure SSO for Workplace Management on the client side.
Retrieve metaData URL
The configuration guides for configuring in your Single Sign On application can be found below.
Info |
---|
Currently, SSO implementation on the side of Workplace Management (and Experience) is always done by the Spacewell Integration team. |
Expand | ||
---|---|---|
| ||
Azure AD Configuration GuideBelow you will find the necessary steps to create a Single sign on application inside the Azure AD portal. Creating Azure application
Setting up single sign onOnce the application is created and you are navigated to the application properties screen.
Automatic using metadata fileThe easiest way to fill in the single sign on settings is through the metadata file. This can be acquired in two ways:
Uploading the metadata
Setting additional claims (optional)If you intend to use the SSO connection in combination with Just In Time Provisioning, you might want to add additional claims. To do this, navigate to “Attributes & Claims” and press “Edit” In the resulting screen, you can add any (group) claims if preferred. If you need further assistance adding these, please consult with your Azure administrator on how to add these. Adding users
Sharing the necessary informationIf you are done with all the above steps, you can share the metadata file from the application with your Spacewell contact. On the SAML-based Sign-on page, navigate to section 3 “SAML Certificates” and share the “App Federation Metadata Url” with your Spacewell contact. They will take the necessary steps on their end to allow the SSO connection to work. Certificate renewals
|
Expand | ||||||||
---|---|---|---|---|---|---|---|---|
| ||||||||
Okta Configuration GuideBelow you will find the necessary steps to create a Single sign on application inside the Okta portal. Creating Okta SSO application
Metadata informationThe easiest way to retrieve the information necessary for the SAML 2.0 connection is through the metadata file. This can be acquired in two ways:
3. Scroll down to the “Attribute Statements (optional)” and add the attributes that should be shared. As a minimal, you should add “user.email”, “user.firstName” and “user.lastName”. Take note of the values in the column “Name”, as those need to be shared with your Spacewell contact. Use the “Add Another” button to add additional attributes if you need those. 4. Press on “Next” 5. In the next screen, set the value to “I’m an Okta customer adding an internal app” and “This is an internal app that we have created”. 6. Click “Finish” 7. In the resulting screen, navigate to the section “SAML Signing Certificates”. Creating Okta Bookmark application (optional)If you would like users to login from Okta into Workplace Management, you will need to make a bookmark application. The SSO application in Okta does not allow a URL to be specified with which a user can login. Adding a bookmark application does make this possible. In Okta, click on “Applications > Applications” followed by “Browse App Catalog”
Assign usersAssigning users applies to at least the SSO application and optionally the bookmark application.
Add application logo (optional)
Certificate renewals
|
Expand | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|
| ||||||||||||
ADFS Configuration GuideBelow you can find the settings that, if used, will lead to a successful SAML connection with Workplace Management. These settings have lead to the most successful connections with clients. Deviating from the below settings might cause billable hours by your Spacewell contact. Settings in ADFSThroughout the images below, you will find references to the server “axpr05”. This should be replaced with your Workplace Management server. You can find this information in thew section below https://spacewell.atlassian.net/wiki/spaces/~62e256719974783acc356c63/pages/128024601. Setup the necessary claims
Custom claimThe custom claim that is used above is setup as follows:
Custom claims in case the above does not workIn the rare case that the above instruction is not sufficient for a working connection, the following custom claims might need to be implemented. All the other claims should be removed. Custom claim 1
Custom claim 2
|
Expand | ||||||
---|---|---|---|---|---|---|
| ||||||
Retrieving Federation Metadata URL for WPM
Inside Workplace Management, navigate to the environment setup by clicking on the “Setup” dashboard button or in the menu on “Admin > Setup”. Take note of the server number The metadata URL can be found by using the following URL: https://axpr00.axxerion.com/axxerion/saml/metadata In this URL, you should replace the 00 with your server number. Be aware: if you are on a server with a single digit 'x', it should be axpr0x. |
Summary
Rw ui textbox macro |
---|
|
Exercise
- N/A
Search
Live Search |
---|