Federated Authentication Settings
9 min
federated authentication enables single sign on (sso) for blueprint using saml 2 0 when configured, users authenticate through your organization's identity provider (idp) — such as microsoft entra id — rather than logging in with a blueprint username and password setup involves two parts configuring an enterprise application in your idp, then configuring blueprint to connect to it part 1 configure the app in microsoft entra id (formerly azure ad) ⓘ throughout these steps, \<yourblueprinturl> refers to the url of your blueprint site (e g , https //demo blueprintcloud com) for blueprint cloud customers, this url was provided to you by support or your success manager create the app navigate to the microsoft entra admin center at https //entra microsoft com go to identity > applications > enterprise applications > all applications select new application select create your own application name your app (e g , "blueprint sso") select integrate any other application you don't find in the gallery (non gallery) select create configure the app navigate to single sign on and select saml edit basic saml configuration and populate the fields based on your sso type sp initiated sso\ sp & idp initiated sso identifier (entity id) \<yourblueprinturl>/login/samlhandler ashx reply url (assertion consumer service url) \<yourblueprinturl>/login/samlhandler ashx sign on url \<yourblueprinturl>/index html relay state and logout url are not required and can be left blank identifier (entity id) \<yourblueprinturl>/login/samlhandler ashx/?host=https%3a%2f%2f\<yourblueprinturl> reply url (assertion consumer service url) \<yourblueprinturl>/login/samlhandler ashx sign on url \<yourblueprinturl>/index html relay state and logout url are not required and can be left blank from the saml certificates section, download the federated metadata xml file ⓘ depending on your corporate it policies and the enterprise application's assignment required setting, you may need to assign users or groups to the application before they can sign in see microsoft's documentation on properties of an enterprise application https //learn microsoft com/en us/entra/identity/enterprise apps/application properties#assignment required and manage users and groups assignment to an application https //learn microsoft com/en us/entra/identity/enterprise apps/assign user or group access portal?pivots=portal#assign users and groups to an application using the microsoft entra admin center for details part 2 configure blueprint in blueprint, navigate to administration > advanced settings > federated authentication settings check enable federated authentication general settings federation type — the federation protocol in use blueprint supports saml 2 0 auto fill with saml metadata — click this button to upload the federated metadata xml file you downloaded from entra id blueprint will automatically populate the identity provider certificate and login settings fields from the file identity provider certificate once the xml file is uploaded, blueprint populates the following read only certificate details issued to — the entity the certificate was issued to valid from — the certificate's start date valid to — the certificate's expiration date fingerprint — the certificate's unique fingerprint hash you can also upload a certificate manually using the upload certificate button login settings login url (required) — the idp url that blueprint redirects users to when initiating sso login logout url (required) — the url users are redirected to after logging out enter your blueprint url (e g , https //demo blueprintcloud com) error url — the url users are redirected to if an sso error occurs login prompt — the text displayed below the login button on blueprint's login page use this to direct users to sign in with sso (e g , "login with microsoft entra id") customize electronic signature prompt — optional custom text for the electronic signature prompt displayed during approval workflows attribute claim rule name (required) — the claim blueprint uses to identify the authenticated user for entra id, enter http //schemas xmlsoap org/ws/2005/05/identity/claims/name to use the user principal name (upn/email address) allow sso user authentication without a domain name — when checked, users can authenticate via sso without specifying a domain name you can also add one or more domain names to restrict sso authentication to specific domains part 3 create blueprint users after configuration is complete, each user's blueprint username must match their microsoft 365 email address (user principal name) to ensure successful authentication for more information, see user management docid\ gmy7lefbkpvijqprsjdm1