SAML through Microsoft Entra ID (fka Microsoft Azure AD)

 

The Infobase platform offers the ability to connect your Microsoft Entra ID for authentication. For more about the Entra ID, see Microsoft's site here. 

Infobase resources are federated in the UK Federation, InCommon, and EduGAIN. The following instructions are for IdPs that are not federated. 

Please note that user provisioning and rostering is not currently supported. The connection works via domain match and will not create a new user in the Infobase system or log a user into their existing personal account. 

This integration uses an OpenAthens connector, but you do not need an OpenAthens account to set this up. For more on their technical requirements for SAML, see this page of the OpenAthens Help Center.

Please follow these steps to set up the Microsoft Entra ID SAML connection:

  1. Include the following entity ID and metadata to the IdPs list of whitelisted SPs:

      • SP Metadata URL:  https://sp.openathens.net/metadata-sp/credoreference.com/235ba2cc-44a1-44fa-a9a3-e9a434dd2930?hostedLogos=false

      • Some services may also require an SP Assertion Consumer Service URL: https://connect.openathens.net/credoreference.com/235ba2cc-44a1-44fa-a9a3-e9a434dd2930/auth/rcv/saml2/post
  1. Share your metadata URL and entity ID with Infobase (support@infobase.com) or use this custom Google form to send us the information.

  2. Ensure that the eduPersonScopedAffiliation attribute is released with the name  urn:oid:1.3.6.1.4.1.5923.1.1.1.9 . This attribute specifies the person's affiliation within a particular security domain in broad categories such as student, faculty, staff, alum, etc. Example values of this attribute are: staff@abccollege.edustudent@abccollege.edu. The part before the @ signifies the affiliation of the user within the domain. The part after the @ can be the domain name. The full set of expected values in this attribute need to be shared with Infobase to complete SAML setup on the account.

0 out of 0 found this helpful