Set Up Azure in Ironclad
- From the Azure main page, click View Manage Microsoft Entra ID.
- In the top bar, click + Add.
- Select Enterprise application.
- On the next screen, in the top bar, click Create your own application. A side panel opens.
- In the What’s the name of your app field, enter Ironclad.
- Select Integrate any other application you don’t find in the gallery (Non-gallery).
- Click Create.
- In the left panel, under the Manage section, click Single sign-on. Select SAML.
- Set up a basic SAML configuration. To do this:
- Next to the Basic SAML Configuration section, click the pencil icon. A panel displays on the right side of the screen.
- In the Identifier field, enter ironcladapp.com.
- In the Reply URL field, enter the Callback URL found on your Ironclad SAML Integrations page.
- Configure the User Attributes & Claims. To do this:
- Next to the User Attributes & Claims section, click the pencil icon. A panel displays on the right side of the screen.
- In the Additional Claims section, enter the following (case sensitive):
- In the Claim name field, enter email. In the Value field, enter user.mail.
- In the Claim name field, enter firstName. In the Value field, enter user.givenname.
- In the Claim name field, enter lastName. In the Value field, enter user.surname.
- Verify the Namespace URL field is blank.
- In the Additional Claims section, enter the following (case sensitive):
- Next to the User Attributes & Claims section, click the pencil icon. A panel displays on the right side of the screen.
- Configure the SAML Signing Certificate. To do this:
- In the SAML Signing Certificate section, locate Federation Metadata XML and click Download. A file named “Ironclad.xml” is downloaded.
- On the Ironclad SAML Integrations page, under IdP Configuration XML, click Upload. Upload the Federation Metadata XML file from Azure.
- Click Save.
- The configuration is complete. You can use the Azure Active Directory to add individual users and groups to Ironclad.
Assign Individual Users to the Ironclad App in Azure
- In your Microsoft Azure portal, click the menu located in the top left, and then click Azure Active Directory > Enterprise applications > All Applications.
- Search for the Ironclad application you created.
- Click Assign users and groups, and then click Add user.
- Click None Selected.
- In the list of users, select the users that you want to add to the Ironclad application.
- Click Select, and then click Assign. Once you receive a confirmation, your users are added to Ironclad.
Assign Groups to the Ironclad App in Azure
- In your Microsoft Azure portal, click the menu located in the top left, and then click Azure Active Directory > Enterprise applications > All Applications.
- Search for the Ironclad application you created.
- Click Assign users and groups, and then click Add user.
- Click None Selected.
- In the list of groups, select the groups that you want to add to the Ironclad application.
- Click Select, and then click Assign. Once you receive a confirmation, the users in that group can log in to myapps.microsoft.com and have access to the Ironclad application.
Source: https://support.ironcladapp.com/hc/en-us/articles/12285954825239-Set-Up-Azure-SSO-SAML-Integration