Configuring Identity for Entra ID

Sally Robinson Updated by Sally Robinson

Configuring Identity with Entra ID

This guide will take you through the steps required to setting up a federation between OneAdvanced Identity (single sign-on) and Entra ID (formerly Azure AD) via the MyWorkplace platform. It is intended for use by Customer Administrators who will have the required permissions to follow the steps correctly.

You may need the help of your IT team to help set up an Enterprise application in Entra ID.

From Entra ID you will need the following for Identity configuration:

• Login URL

• Entra ID Certificate as a Base64 string

From Identity (MyWorkplace) you will need:

• Organisation reference

• Federation alias

• Identity URL

Organisation reference

This will be provided by OneAdvanced Support and be in the format advanced-legal.

It can also be found in MyWorkplace Organisation Manager which you will get access to as part of onboarding to Legal Forms.

Alias

The Alias is a value provided to Entra ID from Identity to allow it to connect to Identity for your organisation. It must be unique within an Organisation but can be repeated across different Organisations.

For use with Entra ID, it is suggested that entraid is used as the alias in order to avoid confusion, but any value can be used so long as it has fewer than 30 characters and only contains lower case letters.

Create a new Entra ID Enterprise Application

  1. Open the Microsoft Entra ID admin centre as an Administrator
  2. Select Identity | Applications | Enterprise applications
  3. In All applications, select New Application
  4. Select Create your own application
  5. Provide a descriptive name e.g. OneAdvanced Identity
  6. Ignore any suggestions made by Entra ID as below
  7. Ensure the default option for Integrate any other application you don’t find in the gallery is selected
  8. Select Create

You will be now taken to the new Enterprise application e.g. OneAdvanced Identity

Configure Single Sign-on

  1. From this window, select Single sign-on followed by SAML
  2. In Step1 - Basic SAML Configuration, select Edit
  3. Enter your Identifier (Entity ID) which will be provided by OneAdvanced Support
  4. Enter your Reply URL which will again be provided by OneAdvanced Support
  5. Select Save
  6. Go to Step 4 – Set up OneAdvanced Identity
  7. Copy the Login URL – this will be needed in Organisation Manager

SAML Certificates

You now need to download the Base 64 Certificate.

  1. Scroll down to Step 3 – SAML Certificates
  2. Select Download next to Certificate (Base64)
  3. Navigate to the folder where the certificate was saved
  4. Right click the file and open with Notepad ++ - you should see something to below
  5. Remove all the text on the BEGIN CERTIFICATE and END CERTIFICATE lines
  6. Save this as a text file as you will need it later

Grant Access to Users

  1. Select Users and Groups
  2. Select Add user/group
  3. Search and select the users or groups who you would like to be able use Identity
  4. Assign the users or groups

Configuring Entra ID with Identity

Before you can finish the configuration between Entra ID and Identity, you will need to create a password and set up multi-factor authentication in order to access Organisation Manager in MyWorkplace.

Setting a password and MFA for the first time

  1. Go to http://myworkplace.oneadvanced.com
  2. For the first time, Users MUST set a password by entering their email address and clicking Reset Password
  3. Re-enter you email address and click Send
  4. An email will be sent with a Change Password link which is only valid for 30 minutes
  5. Click on the Change Password link which will take you to the multi-factor authentication page
  6. Follow the on-screen instructions – see here for Authenticator app examples
  7. Once you have set up the Authenticator app, enter in the Verification code supplied by the app in your browser
  8. Enter the verification code shown in the app into your browser
  9. Click Verify
  10. Enter a new password which must be a minimum of 14 characters
  1. Confirm your password and click Save

Log in to MyWorkplace

  1. Open MyWorkplace - http://myworkplace.oneadvanced.com
  2. Enter your email address and click Continue
  3. If requested, select your Organisation
  4. Enter your newly created password and click Log in
  5. Enter the Verification code from the authenticator app

 

Federating Entra ID with Organisation Manager

  1. In MyWorkplace, go to Apps | System Settings | Organisations
  2. Click on the green Edit button adjacent to your organisation
  3. Select the Single sign-on tab
  4. Select Microsoft Entra ID and complete the following fields
  5. You will need to complete the following fields

Name

Entra ID

The name visible to users if they have the choice of SSO or Username and password

Alias

entraid

This was used in the Entra ID Reply URL set up earlier

Login URL

https://login.microsoftonline.com345ukehfhi

This is the URL that was copied from Entra ID

Certificate

MIIC8DCCAdigAwIBAgIQOnIHVhn4bZBC4Xfjg

The text copied from the text file saved from Entra ID

 

  1. Click Create
  2. You will see Single sign-on with Entra ID

Configure Entra ID in Organisation Manager

Provider tab

  1. From the above screen, select Configure
  2. On the Provider tab, update the following values

First Login Flow

Automatic pairing

This will automatically pair Identity User with Entra Id user

GUI Order

1

If more than one SSO is in use, then this dictates the order. Can be left blank.

Mappers

  1. On the Mappers tab, add the following mappings

Name

Mapper type

Attribute name

Friendly name

User attribute name

Last name

Attribute importer

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

Last name

lastName

Given name

Attribute importer

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

Given Name

firstName

Email

Attribute importer

http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

Email

email

Testing the Solution

In order to test the solution, you can now go through the login process through MyWorkplace.

  1. Go to https://myworkplace.oneadvanced.com
  2. Select Entra ID and you should be routed your Entra ID which will allow you to login with your network credentials 

 

Was this article useful?

Configuring Identity for Azure AD

API Client Id and Client Secret

Contact