Skip to main content

Microsoft Entra ID / Azure AD — SAML setup with iGrafx Identity

Configure Microsoft Entra ID (Azure AD) as the SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. identity provider for the iGrafx Identity Solution.

Prerequisites

  • Access to the Azure portal with permission to create an enterprise application.
  • Your Tenant ID and the region-specific reply URL from iGrafx (used below as YourTenant).

Steps

Create the enterprise application

  1. In the Azure portal, search for and select Enterprise applications.

  2. Click New application.

  3. On the Microsoft Entra Gallery page, click Create your own application.

  4. Enter a name for the application.

  5. Select Integrate any other application you don't find in the gallery (Non-gallery).

  6. Click Create.

  7. In the new enterprise application, open the Single sign-on blade.

  8. Select SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO..

  9. Click Edit to configure SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO..

    The SAML single sign-on configuration in the enterprise application.

Configure the basic SAML settings for your region

Europe / EMEA:

  1. Identifier (Service Provider Entity ID): https://id.igrafxcloud.eu/realms/igrafx
  2. ACS / Reply URL: https://id.igrafxcloud.eu/realms/igrafx/broker/YourTenant-idp-1/endpoint (iGrafx provides your specific Reply URL).
  3. Sign on URL: https://YOUR_SUBDOMAIN.igrafxcloud.com

Rest of the world / NA:

  1. Identifier (Service Provider Entity ID): https://id.igrafxcloud.com/realms/igrafx
  2. ACS / Reply URL: https://id.igrafxcloud.com/realms/igrafx/broker/YourTenant-idp-1/endpoint (iGrafx provides your specific Reply URL).
  3. Sign on URL: https://YOUR_SUBDOMAIN.igrafxcloud.com

Click Save.

The completed basic SAML configuration.

Finish and send the metadata

  1. The Attributes & Claims section is usually correct — leave it unchanged.

  2. Copy the SAMLSAML An XML-based standard for exchanging authentication and authorization data between an identity provider and a service provider. Process360 Live supports SAML 2.0 for SSO. metadata URL (the copy button in that section) to provide to iGrafx.

    Copying the SAML metadata URL.

  3. Configure the groups and users allowed to use SSOSSO An authentication scheme that lets users sign in once with an identity provider and access Process360 Live without re-entering credentials. with the enterprise application.

    Assigning users and groups to the enterprise application.

  4. After you send the metadata URL to iGrafx, the iGrafx team configures the iGrafx IdentityiGrafx Identity The iGrafx identity and access management service that brokers authentication between customer identity providers and Process360 Live components. Solution and tells you when it's ready to test.