Setting up single sign-on for an enterprise application
Once the application is created, you can set up single sign-on for your application.
To set up single sign-on:
- Go to Azure Active Directory > Enterprise applications.
- In Enterprise applications, enter the name of your enterprise application in the search bar, and click the application to open it.
See Creating an enterprise application in Azure Portal.
- Select Get Started in Set up single sign on.
- In Single sign-on, select SAML.
The SAML-based Sign-on window opens.
- In the SAML-based Sign-on window, select Edit in the Basic SAML Configuration pane.
- In the Basic SAML Configuration window, enter the following information from the FortiAuthenticator SP:
- In Identifier (Entity ID), enter the SP entity ID.
- In Reply URL (Assertion Consumer Service URL), enter the URL where the application receives the authentication token.
- In Sign on URL, enter the URL for the sign-in page for the application.
- In Relay State, enter the URL to which the user is redirected to by the SP after a successful assertion response.
- In Logout Url, enter the URL used to send the SAML logout response back to the application.
- Click Save.
See Adding a user group SAML attribute to the enterprise application and Adding users to an enterprise application.