Skip to main content

Setting up (SSO) SAML with Safeguard

Guus de Zwart avatar
Written by Guus de Zwart
Updated over 2 months ago

Follow the steps below to configure Single Sign-On (SSO) for Safeguard using SAML in Microsoft Entra ID (formerly Azure Active Directory).

Step 1: Create an Enterprise Application

  1. Navigate to Applications > Enterprise applications.

  2. Click + New application.

  3. Select Create your own application.

  4. Enter a name (e.g., “Safeguard”) and choose Integrate any other application you don’t find in the gallery (Non-gallery).

  5. Click Create.


Step 2: Set Up Single Sign-On

  1. After the application is created, go to Single sign-on in the left-hand menu.

  2. Select SAML as the sign-on method.


Step 3: Upload Our Metadata File

  1. Click Upload metadata file at the top and select the metadata file we provided.

  2. All necessary fields will be filled in automatically after upload.

  3. Click Save.


Step 4: Configure the SAML Signing Options

  1. Scroll down to the SAML Certificates section.

  2. Click Edit next to the Token signing certificate (pencil icon).

  3. Under Signing Option, select:
    - Sign SAML response

  4. Set Signing Algorithm to:
    - SHA-256

  5. Click Save.


Step 5: Assign Users or Groups to the Application

  1. In the left-hand menu of the application, go to Users and groups.

  2. Click + Add user/group.

  3. Select the users or groups who should have access to the application.

  4. Click Assign.

  5. Only assigned users will be able to sign in via SSO. Make sure to include at least one user for testing in the next step.

Step 6: Share the Federation Metadata URL

  1. In the SAML Certificates section, find the App Federation Metadata Url.

  2. Copy the URL and share it with our support team at [email protected].


Step 7: Test the Sign-In and Finalize Setup

  1. Coordinate with our support team to test the SSO integration.

  2. We’ll verify that the SAML response is received correctly and that user access works as expected.

  3. Once the test is successful, we’ll finalize the configuration on our side and confirm that everything is ready for use.

If you haven’t already, please contact our support team at [email protected] to schedule the test.

Did this answer your question?