Assembled supports signing in with Microsoft Entra ID (formerly Azure AD) using SAML single sign-on (SSO). This article walks through registering Assembled as an enterprise application in Entra, sharing your SAML details with our support team, and testing the connection before you roll it out to your organization.
If your team uses Okta instead, see How to configure Okta for Assembled. For general background on how SAML SSO works with Assembled, see How to configure SAML SSO for Assembled. If you also want to automate user provisioning, see SCIM User Provisioning.
Access: you'll need Global Administrator or Application Administrator access in your Microsoft Entra tenant, plus an Assembled-provisioned company account. If you don't have an Assembled account yet, contact support@assembled.com to request one.
What do I need before I start?
Setting up Entra SSO is a joint process between your Entra administrator and the Assembled support team. Before you start, contact support@assembled.com to let us know you're setting up Microsoft Entra SSO. We'll provide the Assertion Consumer Service (ACS) URL and Entity ID that are unique to your Assembled account, which you'll need in Entra.
Note: Assembled supports SP-initiated SAML SSO. Users sign in by going to their Assembled login URL, and are redirected to Entra to authenticate if they don't already have an active session.
How do I register Assembled as an enterprise application in Microsoft Entra?
- Sign in to the Microsoft Entra admin center with an account that has Global Administrator or Application Administrator access.
- Navigate to Identity > Applications > Enterprise applications.
- Select + New application.
- Select Create your own application.
- Enter a name, such as Assembled, and select Integrate any other application you don't find in the gallery (Non-gallery).
- Select Create.
This creates the application object you'll use to configure single sign-on and assign users in the following steps.
How do I configure single sign-on for the application?
- From your new application, select Single sign-on in the left navigation.
- Select SAML as the single sign-on method.
- In the Basic SAML Configuration section, select Edit.
- Enter the Entity ID Assembled provided you in the Identifier (Entity ID) field.
- Enter the ACS URL Assembled provided you in the Reply URL (Assertion Consumer Service URL) field.
- Select Save.
Important: the Entity ID and ACS URL are unique to your Assembled account. Using placeholder or example values will cause sign-in to fail. If you haven't received yours yet, contact support@assembled.com before continuing.
How do I assign users or groups to the Assembled application?
Users and groups need to be assigned to the enterprise application in Entra before they can sign in to Assembled through SSO.
- From your application, select Users and groups in the left navigation.
- Select + Add user/group.
- Choose the users or groups who should have access to Assembled, then select Assign.
Keep in mind: a user must already have an Assembled account, or be provisioned through SCIM, before they can sign in through SSO. Assigning a user in Entra alone doesn't create their Assembled account.
How do I share my SAML metadata with Assembled and test the connection?
- From your application's Single sign-on page, find the SAML Certificates section.
- Download the Federation Metadata XML file.
- Send this file to support@assembled.com.
Once we receive your metadata file, we'll configure the connection on our end and let you know when it's ready to test. To test, sign in to Assembled with a test account before rolling SSO out to your whole team. This can take a few business days depending on our support queue.
How do I enforce SSO for my entire organization?
Once your connection is tested and working, you can choose to require SSO for all sign-ins. Let support@assembled.com know if you'd like to enable this.
Important: enforcing SSO disables all other sign-in methods, including password and Google sign-in. Share a preferred date and time with your Assembled contact so we can plan the rollout and help avoid locking anyone out.
Questions? Contact support@assembled.com and we'll be glad to help.
Comments
0 comments
Article is closed for comments.