Set up SSO with Microsoft Entra

AI Tools

My OPSWAT Portal offers an integration with a 3rd-party Single Sign-on Service (SSO).

My OPSWAT Portal uses the secure and widely adopted industry standard Security Assertion Markup Language 2.0 (SAML 2.0), so that you can integrate easily with any identity provider that supports SAML 2.0.

To get started, log into Microsoft Entra and create an application for My OPSWAT Portal . Details can be found here

  1. Log into Microsoft Entra as an Administrator

  2. Select Application Enterprise applications → ”New Application”

  3. Select “Create Your own Application”

  4. Input Application Name into "What's the name of your app?" field and select “Integrate any other application you don't find in the gallery (Non-gallery)” → Click Create button

  5. After the Create new application finished. In the middle of page, choose “Set up single sign on”


  6. Select SAML method


  7. At SAML Certificate section → App Federation Metadata Url → Copy the XML file/URL. URL example: https://login.microsoftonline.com/xxxxxxx/federationmetadata/2007-06/federationmetadata.xml?appid=xxxxxxxx


  8. Contact My OPSWAT support team via Support Service and provide all below info:

    • Ticket Summary: “Integrate Microsoft Entra with My OPSWAT Portal”

    • Description:

      • Customer Company Name:<your company name>

      • Domain name: <opswat.com (It must be a valid domain, if not it will not be accepted)>

      • Sample user*: <user_email> * To minimize the risk of blocking all users in the domain from signing in if there is an issue with the SSO configuration, we would like to enable SSO for a single test user first. Once you confirm that everything is working correctly, we will roll it out to all users in the domain.

      • The XML file/URL: <Which is downloaded from step #7>

      • How many users?

      • Do you have Organization?

        • No: please provide Organization name, email of the first Admin.(We will create an Organization and add the first Admin for this Org, then you can invite user to the Organization)

        • If Yes: skip this info

      • OPSWAT will redirect users to authenticate by the configured IDP based on provided domain or specific user. Do you have any specific users in IDP with different domain emails?

        • If No: skip this info

        • If Yes: Please provide a list user emails

  9. Waiting response from Support Team, they will provide back to you:

  10. At “Basic SAML Configuration" section, Setup ACS Url and Entity ID with data is received from step #9


  11. [Option] If you change or add any attributes or claims in the Attributes & Claims section, please let us know. Otherwise, you can keep the default configuration for a stable setup.


  12. Now you need to assign people/groups who can access this application on Microsoft Entra. On the left menu, select Users and groupsAdd user/group.


Info

After the user signs in to My OPSWAT Portal using Single Sign-On (SSO), the Admin must manually invite the user to the Organization, or the user needs to send a request to join. This is required in order to share organization entitlements.

Warning

If user is created without emailAddress, lastName, firstName info on Microsoft Entra, the user cannot single sign-on My OPSWAT Portal.