Set up Microsoft Entra SAML and SCIM for airfocus

Written by:  Morgan T
Last updated:  

This article outlines the setup instructions for Microsoft Entra SCIM with airfocus. You can use SCIM to provision, update, and de-provision users in airfocus from Microsoft Entra.

Microsoft Entra airfocus app setup

Navigate to MS Entra: https://entra.microsoft.com

  1. Select “Enterprise apps” on the left-hand sidebar.
    entra-id-click-enterprise-apps.png
  2. Select “New application”.
    ms-entra-select-new-application.png
  3. Select “Create your own application”.
    ms-entra-create-your-own-application.png
  4. Name your app (e.g. “airfocus”).
  5. Select “Integrate any other application you don’t find in the gallery (Non-gallery)”.
  6. Click “Create”.
    ms-entra-finish-creating-application.png

SCIM setup

Navigate to your Microsoft Entra airfocus app (created in the steps above).

  1. Select “Provisioning” from the “Manage” menu.
    ms-entra-provisioning-tab.png
  2. Click “Connect your application”.
    ms-entra-connect-your-application.png
  3. In a new tab, login to airfocus.
  4. In the sidebar, at the bottom left, click on your profile and team settings.
    ms-entra-click-user-and-team-settings.png
  5. Go to the Security/SSO tab and click on manage next to single sign-on.
    ms-entra-security-sso.png
  6. Enable SCIM and keep track of the base URL and generated token/secret.
    ms-entra-base-url-example.png
  7. Back in Microsoft Entra, paste the value for “airfocus SCIM base URL” as the Tenant URL and the value for your generated SCIM token as the Secret Token.
    • Test the connection to verify Microsoft Entra can connect to your airfocus team instance, then click “Create”.
      ms-entra-paste-base-url-and-test-connection.png
  8. Ensure that you enable provisioning by clicking “Provisioning” for your application, then setting the “Provisioning Status” toggle to “On”.
    ms-entra-save-provisioning-and-turn-on.png
  9. To assign users to your application, click “Users and groups” under the “Manage” menu.
    ms-entra-assign-users.png
  10. Add any users you want to provision or set up SAML logins for.
    • Adding a group of users will create a new member group in airfocus and provision all users within that group. Learn more about airfocus member groups in our Manage members, roles, and permissions in airfocus article.
    • It can take around 40 minutes for Microsoft Entra to provision the users in airfocus.
      ms-entra-add-user-or-group.png

SAML setup

Follow these steps to set up SAML:

  1. Log in into airfocus.
  2. At the bottom left, click on your profile and team settings.
    ms-entra-click-user-and-team-settings.png
  3. Go to the Security/SSO tab and click "manage" next to single sign-on.
    ms-entra-security-sso.png
  4. Click "Set up SAML SSO".
    ms-entra-set-up-saml-sso.png
  5. Keep track of the single sign-on URL and entity ID; you will need it when setting up SAML in Microsoft Entra.
    ms-entra-sso-url-and-entity-id-example.png
  6. Select “Single sign-on” in the “Manage” menu of your MS Entra airfocus app.
    • Make sure you select the “Enterprise Application” (or “Service Principal”) for the app. Selecting the “App registration” won’t show the SAML configuration UI.
      ms-entra-single-sign-on-tab.png
  7. Select “SAML” as the single sign-on method.
    ms-entra-select-saml.png
  8. Click “Edit” under the “Basic SAML Configuration” pane.
    ms-entra-select-edit-in-basic-saml-configuration.png
  9. Add the values obtained earlier from the airfocus SSO settings page under the “Reply URL” and “Identifier” fields as follows, then click “Save.”
    ms-entra-finish-basic-saml-configuration.png
  10. Go back to your enterprise application’s Single sign-on page and download the Federation Metadata XML.
    ms-entra-download-federation-metadata-xml.png

To finish, configure the values in the airfocus SSO settings page by doing the following: 

  1. Click “Upload” in the airfocus SSO settings page and select the XML file that was just downloaded.
    ms-entra-upload-idp-definition.png
  2. Click the “Test” button to test the connection to your Microsoft Entra instance.
    • The connection will only work if the Microsoft Entra airfocus app has been assigned to the user you’ll sign in with to test the connection.
    • In Microsoft Entra, you can assign the app to users in the Assignments section of the app page. To do so, navigate to “Users and Groups” on the left hand side and click "Assign".
      ms-entra-test.png
  3. After a successful connection, click “Apply” to apply the configuration.
    ms-entra-apply-configuration.png

You can now sign in to airfocus via SAML through Microsoft Entra! Remember to assign users who should be able to login via SAML to the airfocus app in Microsoft Entra.

Give feedback on this article

Have feedback about this article? Tell us about your experience here.

Did you find what you were looking for?

Still have a question or want to share what you have learned? Visit our Community   to get help and collaborate with others.