This article will walk you through how to set up Microsoft Entra ID (Azure) SSO/SAML integration in Ironclad.
Disclaimer: If you change your domain, your access to Ironclad is prohibited. Before migrating your domain, submit a request with our Support Team for assistance.
Set Up Microsoft Entra ID (Azure) in Ironclad
- From the Microsoft Entra ID main page, under Manage Microsoft Entra ID, click View.
- In the top bar, click + Add.
- Select Enterprise application.
- On the next screen, in the top bar, click Create your own application. A side panel opens.
- In the What’s the name of your app field, enter Ironclad.
- Select Integrate any other application you don’t find in the gallery (Non-gallery).
- Click Create.
- In the left panel, under the Manage section, click Single sign-on. Select SAML.
- Set up a basic SAML configuration. To do this:
- Next to the Basic SAML Configuration section, click the pencil icon. A panel displays on the right side of the screen.
-
In the Identifier field, enter na1.ironcladapp.com (or the exact value shown under Company Settings > Integrations > SAML > Show Additional IdP Settings > Service Provider Identifier in Ironclad)
- In the Reply URL field, enter the Callback URL found on your Ironclad SAML Integrations page (Company Settings > Integrations > SAML).
- Configure the User Attributes & Claims. To do this:
- Next to the User Attributes & Claims section, click the pencil icon. A panel displays on the right side of the screen.
- In the Additional Claims section, enter the following (case sensitive):
- In the Claim name field, enter email. In the Value field, enter user.mail.
- In the Claim name field, enter firstName. In the Value field, enter user.givenname.
- In the Claim name field, enter lastName. In the Value field, enter user.surname.
- Verify the Namespace URL field is blank.
- In the Additional Claims section, enter the following (case sensitive):
- Next to the User Attributes & Claims section, click the pencil icon. A panel displays on the right side of the screen.
- Configure the SAML Signing Certificate. To do this:
- In the SAML Signing Certificate section, locate Federation Metadata XML and click Download. A file named “Ironclad.xml” is downloaded.
- On the Ironclad SAML Integrations page (Company Settings > Integrations > SAML)
- , under IdP Configuration XML, click Upload. Upload the Federation Metadata XML file from Azure.
- Click Save.
The configuration is complete. You can use the Azure Active Directory to add individual users and groups to Ironclad.
Assign Individual Users to the Ironclad App in Microsoft Entra ID
To assign individual users to the Ironclad app in Microsoft Entra ID:
- In your Microsoft Azure portal, click the menu located in the top left.
- Click Microsoft Entra ID > Enterprise applications > All Applications.
- Search for the Ironclad application you created.
- Click Assign users and groups, and then click Add user.
- Click None Selected.
- In the list of users, select the users that you want to add to the Ironclad application.
- Click Select, and then click Assign.
- Note: Upon login to Ironclad, if the user sees the Ironclad Dashboard, the Microsoft Entra ID configuration was a success. If there are users provisioned within Ironclad prior to setting up SSO, these users will remain password login users. Reach out to Ironclad Support for assistance migrating existing Ironclad users from password login to SSO login.
Once you receive a confirmation, your users are added to Ironclad.
Assign Groups to the Ironclad App in Microsoft Entra ID
To assign groups to the Ironclad app in Microsoft Entra ID:
- In your Microsoft Azure portal, click the menu located in the top left, and then click Microsoft Entra ID > Enterprise applications > All Applications.
- Search for the Ironclad application you created.
- Click Assign users and groups, and then click Add user.
- Click None Selected.
- In the list of groups, select the groups that you want to add to the Ironclad application.
- Click Select, and then click Assign.
Once you receive a confirmation, the users in that group can log in to myapps.microsoft.com and have access to the Ironclad application.