Set up SSO¶
The following requirements must be met:
- ☑ All users accessing the Myra App via SSO already have an account in the Myra App. To add new users to the Myra App, see Section User management.
- ☑ The email addresses of users in the Myra App must be identical to the email addresses stored in your IdP.
- ☑ Provide the following information about your IdP:
- Entity ID
- SSO URL of the IdP
- SSO certificate
- Link to the SAML metadata file (optional)
- SAML attribute for transferring the email address (optional)
Proceed as follows to set up SSO:
- ► Open the SSO settings, see Section SSO Configuration tab.
-
► Check whether the switch under SSO STATUS is disabled.
Note
Do not activate the switch until you have configured and saved all settings for single sign-on (SSO).
-
► To copy the metadata link of Myra's SAML service provider (SP), click on the icon
in the text field under YOUR SSO METADATA LINK. -
► Add the metadata link or the information it contains to your IdP configuration.
Note
For a detailed description of SAML metadata, refer to your identity provider (IdP) manual.
-
► In the text field under ENTITY ID enter the unique identifier of your IdP.
Note
This is generally a URL or URI that matches the
EntityIDattribute in your IdP’s SAML metadata file. Alternatively, the identifier can also form part of your IdP’s SAML app setting.Example
https://login.microsoftonline.com/<tenant-id>/ -
► In the text field under IDP SSO URL enter the SSO URL of your IdP to which authentication requests should be sent.
Note
In your IdP's SAML metadata file, marked with the attribute
SAML EndpointorLogin URL.Example
https://login.microsoftonline.com/<tenant-id>/saml2 -
► Upload the SSO certificate at SSO Certifikate using one of the following methods.
-
▷ If you want to upload an SSO certificate file from your computer, click on the File upload tab.
- ▷ Click on the Upload file button and select the SSO certificate on your computer.
-
↳ Alternatively, you can drag and drop the SSO certificate into the corresponding box in the SSL/TLS certificate area.
- ▷ If you want to enter the SSO certificate as text, paste the text into the corresponding field and click on the Text field tab.
-
-
► If necessary, enter the name of the attribute containing the email address for logging in via SSO in the text field under EMAIL (OPTIONAL).
Note
You only need to fill in the EMAIL (OPTIONAL) field if your IdP does not use the default value
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressfor transferring the email address.If your IdP differs from the default value, enter the exact name of the attribute that transfers the email address in the field, for example,
EmailorMail. -
► Optionally, add the path to your SAML metadata file in the text field under Metadaten-URI of the IDP.
Note
The SAML metadata file is not necessary if you have manually entered the SSO URL, entity ID, and SSO certificate.
If you do enter the SAML metadata file, we will use it as a backup to review your settings if there is a problem and correct them if necessary.
-
► Check all entries.
- ► To save the settings, click on the Save button.
- ➔ The settings for SSO have been saved and can be tested.