Setting up a SAML2 SSO requires configuration in both the TinQwise platform and an "identity provider". Microsoft Azure is a common identity provider, and this article will show you how to set it up.
In Azure, you'll be creating an enterprise application in Microsoft Entra (formerly called Azure Active Directory or Azure AD). Start by logging in to the Azure portal and going to Microsoft Entra.
Step A: Create the enterprise application
In the left-hand menu, go to Enterprise applications
Click + New application
Select Create your own application
Enter a name for the application: TinQwise and select the Non-gallery option
Step B: Set up single sign on
Click "Set up single sign on" (from the application you just created above)
Select SAML as the single sign-on method
Download your metadata file from
https://[yourplatformname].platform.co.nl/saml2/metadata/
Save this file on your computer.
In Azure, click Upload metadata file
Step C: Copy the metadata URL
After uploading (step B.5 above), copy the App Federation Metadata Url
π Use this URL when configuring the SAML connection on the TinQwise platform
πΈ Reference: Default settings in Azure
These are the default SAML settings after uploading the metadata file:
Basic SAML Configuration
Identifier (Entity ID)
βhttps://[yourplatform].platform.co.nl/saml2/metadataReply URL (Assertion Consumer Service URL)
βhttps://[yourplatform].platform.co.nl/saml2/acs/Logout URL (Optional)
βhttps://[yourplatform].platform.co.nl/saml2/ls/
Attributes & Claims
Required claim:
Claim name | Value |
Unique User Identifier (Name ID) |
|
Additional claims:
Claim name | Value |
|
|
|
|
|
|
|
|









