By centralizing authentication with Microsoft Entra ID, you ensure that your team can securely access OnceHub using their existing corporate credentials, which enhances security and simplifies the overall login process.
This article guides you through the end-to-end process of creating a SAML 2.0 integration between OnceHub and Entra ID, from initial app creation to final user assignment and verification.
Step 1: Create a New Application Integration in Entra ID
In Entra ID, follow the steps below to create a new SAML application integration:
- Select Enterprise apps from the left navigation menu.
- Click New application in the top left of the screen.
- Click Create your own application in the top left of the screen.
- Provide a name for the app.
- Select Integrate any other application you don’t find in the gallery (Non-gallery).
- Click Create.
Step 2: Set Up the SAML Configuration in Entra ID
To configure the SAML settings within Entra ID, you will need to enter credentials provided by OnceHub.
Finding the Credentials within OnceHub
In OnceHub, follow these steps to open the SAML Configuration pop-up with the required credentials:
- Click the Gear icon in the top-right corner.
- Select Security (and Compliance) from the dropdown.
- Click Setup next to Set up SAML configuration for SSO.
Setting Up the Basic SAML Configuration within Entra ID
In Entra ID, follow the steps below to complete the configuration:
- Click Single sign-on from the left navigation menu of the created app.
- Select SAML as the sign-on method.
- Click Next.
- Click Edit in the Basic SAML Configuration tile.
- Copy over the following details from the OnceHub pop-up:
- Click Save.
|
In Entra ID |
In OnceHub |
|
Microsoft Entra Identifier |
Identifier URL |
|
Reply URL |
ACS URL |
|
Sign on URL |
Single sign-on URL |
Setting Up the User Attributes & Claims within Entra ID
In Entra ID, follow the steps below to complete the configuration:
- Go to the previous page in your browser (The Single sign-on page).
- Click Edit in the User Attributes & Claims tile.
- Click Add new claim in the top left of the screen.
- Enter the word email as the name.
- Expand Claim conditions and add the following 2 conditions:
- Click Save.
|
User type |
Scoped Groups |
Source |
Value |
|
Members |
Leave as is. |
Attribute |
user.userprincipalname |
|
All guests |
Leave as is. |
Attribute |
user.mail |
Step 3: Configure the SAML Settings in OnceHub
After the configuration within Entra ID is completed, you will now need to enter credentials provided by Entra ID into your OnceHub account.
Finding the Credentials within Entra ID
In Entra ID, follow these steps to access the page containing the necessary credentials:
- Go to the previous page in your browser (The Single sign-on page).
- Download the Certificate (Base64) in the SAML Signing Certificate tile.
- Scroll down to the Set up {Your App Name} tile to use in the steps below.
Configuring the SAML Settings within OnceHub
In the SAML Configuration pop-up within OnceHub, follow these steps:
- Click Continue to go to the Required by OnceHub tab.
- Copy over the following details from Entra ID:
- Click Save & continue.
|
In Entra ID |
In OnceHub |
|
Microsoft Entra Identifier |
Entity ID |
|
Login URL |
IDP single sign-on URL |
|
Certificate (Base64) text |
Public x509 certificate |
Step 4: Assign the OnceHub SAML 2.0 application to Users in Entra ID
In Entra ID, follow the steps below to assign the new OnceHub SAML 2.0 application to the users who will be utilizing SSO to sign into your OnceHub account:
- Select Enterprise apps from the left navigation menu.
- Open the application you created for OnceHub.
- Click Users and groups from the left navigation menu of the created app.
- Click Add user/group in the top left of the screen.
- Under Users, click None Selected.
- Select the user.
- Click Select.
- Click Assign.
Step 5: Verify the Configuration in OnceHub
In OnceHub, click Verify to do the final verification for both OnceHub and Entra ID. Click Close once the verification is successful.
Step 6: Enable SSO for All Users in OnceHub
In OnceHub, once you've verified your SSO configuration, you can toggle on Enable SSO for all Users.