Note: The MSA agreement must be reviewed and accepted first by the account Admin before going through this process! Trials should complete this SSO Setup process before the expiration date to ensure full functionality post-purchase.
Contents
- Create application
- Assign user access
- SAML configuration
- Download Base64 Certificate
- Return to ActivTrak SSO page
- User provisioning (must be done manually)
- Test your credentials
Create application
- Navigate to https://portal.azure.com/ and log in
- Then find Azure Active Directory > Enterprise applications in the sidebar menu
- Click the + Add new application button in the top left corner
- Click + Create your own Application
- Next, click "Integrate any other application you don't find in the gallery (Non-gallery)"
- Create a name for the instance and click the add button at the bottom left
Assign user access
- Navigate to Users & groups from the side navigation menu
- Then click the + Add new users and groups button in the top left corner
- Select “none selected”
- A menu bar will appear on the right, add the necessary users, and/or groups. Once the groups/ users are chosen, click the Select button at the bottom left corner of the pane
SAML configuration
- Navigate to enterprise applications and click on the name of the instance that was just created
- Select Single Sign-On from the sidebar menu
- Create your own application SSO (SAML) by clicking SAML as shown below
- Fill out the fields as follows:
- Identifier (Entity ID): https://app.activtrak.com/
- Reply URL (Assertion Consumer Service URL): https://auth.activtrak.com/sso/saml/assertion/
- Sign on URL: (leave blank)
- Confirm that only the Identifier & Reply URL are filled in and click Save.
Download Base64 Certificate
- As shown below, where it says Certificate (Base64), click download
- Open this in a text editor such as Notepad
- Copy the text
- Log in to your ActivTrak dashboard
- On the panel on the left, go to Settings > Security > Configuration
- Paste this download into the certificate box between Begin Certificate and End Certificate
Note: Please ensure that only the certificate is being copied & pasted into the box. Extra return characters may cause errors.
- Copy the contents below from Azure and paste them into the ActivTrak dashboard
- Copy the login URL
- Copy the Azure AD Identifier (which will go into the SAML Issuer ID as shown below)
Return to ActivTrak SSO page
- Make sure Enabled is selected under Single sign-on
- Make sure that "Azure AD" is entered in the provider name
- Grab the login URL you took from Azure and paste it into the login URL field
- Grab the Azure AD Identifier you got from Azure and paste the SAML Issuer ID
User provisioning (must be done manually)
- On the panel on the left, go to Settings > Access > App Access
- Select SSO as the Auth. Method in the right-most column for each user who should use single sign-on
Note: The currently logged-in user cannot modify their own SSO settings. If they do, they may be locked out of the account. Another Admin can change this setting for you. Alternatively, please contact support@activtrak.com if you have an account with only a Single Admin.
Test your credentials
- Go to app.activtrak.com
- Select SSO
- Enter your email (You should now authenticate using your Azure Credentials)
- Once SSO is enabled for the User Account, you will not be able to enter a password for authentication on Activtrak's side.