Search

Single Sign-On (SSO) - Microsoft Entra ID

Introduction and scope

This article is a guide to setting up the SSO integration. Emply is build so you as a customer can set up the integration using the SAML method.

Requirements for setup

Permission and access to modify your setup in Microsoft Entra ID.

Preparation for setup

Make sure that your IT consultant has the user role 'IT' in Emply, and has the right to administre integrations.

Create an 'IT' role in Emply under Settings > Account > Roles > select 'New role' > enter title and select 'IT' under 'Import settings'.

IT.png

Your HR department or Emply Customer Relations can create the role and give the IT consultant access to Emply. 

NOTE: 'Nested Groups' are not supported. 

Setting up Single Sign-On

Login to Microsoft Entra ID as administrator https://portal.azure.com.

Go to Enterprise Applications:

sso1.png

Click on 'Add an application'.

sso2.png

Choose SAML 1.1 Token enabled LOB App:

sso3.png

Configuring SAML-based Sign-on

  1. Identifier, Reply URL and Sign-On URL are set to your domain
  2. Attributes & Claims are set as below

sso4.png

3. Copy 'App Federation Metadata Url':

sso5.png

Then log in to your Emply solution with an administrator / IT role. You may need to use this URL to log in: customer.emply.com/login.

Skærmbillede 2024-07-23 kl. 11.26.53.png

Go to Settings > Integrations > find 'Single Sign-On using SAML' and click on Activate.

mceclip0.png

Paste the copied 'App Federation Metadata URL' under 'SAML 2.0 federation metadata URL', as shown in the screenshot below:

mceclip1.png

Select the lowest access level for the 'Default user role'. This is often 'Recruitment Team', which is last in the list.

For 'Requires Single Sing-On', you can select 'Not Required' or 'Required'. If you select 'Required', it is not possible for external consultants to log in.

Finally, press Activate in the bottom of the window.

Test from Microsoft Entra ID

sso6.png

Troubleshooting

Once you have followed this guide and users are experiencing problems logging in, you can enable 'Show claims from SAML server' in the Single Sign-on app in Emply. You will then be able to test the login again and get further information about challenges logging in with SSO.

Was this article helpful?

Was this article helpful?

Want to get in touch?

We got you. Fill out a request and we'll get back to you as soon as possible.

Submit a request