Azure
Please note: Changing the login method to identity provider involves permanently deleting all existing members. Your team members will be automatically added to GoodAcces upon their first login. Currently added devices will be retained.
In case you have problem with login in with SSO (white page; Error: not_a_saml_app) try to clear your cookies and caches, then try to log in with SSO again. If the problem persists, please contact our support.
In the GoodAccess Control Panel, go to Settings, switch to the Login & Security tab and click on Azure.

Gather the following details to be used later:
- Entity ID
- Assertion Consumer Service URL
- Login URL
- Relay State
%20(1).png?alt=media&token=6eb168fa-6a05-4d70-90ab-e1713b19f0fb)
Create your application in Azure - Enterprise Applications

Enter the name and choose "Integrate any other application you don't find in the gallery (Non-gallery)".

Open your new app and continue with the single sign-on and SAML.

Open the Basic SAML Configuration and enter the details from step 2:
- Identifier (Entity ID) - Service Provider Links Entity ID
- Reply URL (Assertion Consumer Service URL) - Assertion Consumer Service URL
- Sign on URL - https://sign.goodaccess.com/
- Relay State - "/" (enter slash)
Delete automatically added URL from Identifier (Entity ID)
Don't forget to Save.

Continue with Edit User Attributes & Claims and edit following:

1) USER.MAIL
- Name - Enter "email"
- Namespace - Leave blank
- Source - Choose Attribute
- Source Attribute - Enter "user.mail"
.png?alt=media&token=9e5ddfdf-2589-4e55-b9f4-c6f61eade025)
2) USER.PRINCIPALNAME
- Name - Enter "name"
- Namespace - Leave blank
- Source - Choose Attribute
- Source attribute - Enter "user.userprincipalname"
.png?alt=media&token=88f7ae72-8678-4f0a-b6a6-ea34ebadc461)
Download the Azure certificate and gather the Login URL and Azure AD Identifier for the next step.
.png?alt=media&token=82e1d0cd-7e53-458a-a9df-f487f556cff6)
In the GoodAccess Control Panel enter the following details from the previous step:
- Sign in URL - Login URL
- Entity ID - Azure AD Identifier
- X509 Signin certificate - Upload Azure certificate
Don't forget to Save Changes.
.png?alt=media&token=9de0d5f2-8fe7-410c-a9ab-aef1c9c99d33)
You can now connect with Azure SSO.
.png?alt=media&token=fefab9a0-7a2d-4cfe-836a-b59cc6f16ed3)
Last modified 6mo ago