VeraLab SSO Integration with Microsoft Azure SAML

VeraLab guide · Download as PDF · All documentation

This guide is for VeraLab administrators and the Microsoft Entra ID (Azure) administrators they work with. It shows how to set up SAML single sign-on (SSO) so that users sign in to the VeraLab web application with their Microsoft accounts.

You will register VeraLab as an enterprise application in the Microsoft Entra admin center, exchange SAML metadata between Entra and VeraLab, map the user attributes VeraLab needs and test the sign-in. You need a VeraLab account with the Administrator role, access to the Microsoft Entra admin center, and HTTPS enabled on your VeraLab server.

Create the Enterprise Application in Microsoft Entra

  1. Log in to the Microsoft Entra admin center and go to Identity → Enterprise applications → Create your own application. Give the application a name, for example VeraLab Test or VeraLab Prod depending on your environment. Keep the default Integrate any other application… option and click Create at the bottom of the panel.
    Microsoft Entra Browse Gallery page with the Create your own application panel, the name VeraLab Prod and Integrate any other application selected
    Creating your own application in the Microsoft Entra admin center.
  2. On the application's Overview page, click Get started in the Set up single sign on block.
    VeraLab Prod enterprise application Overview page with the Set up single sign on Get started link circled
    The application Overview page: Set up single sign on.
  3. Under Select a single sign-on method, click the SAML block.
    Select a single sign-on method page in Microsoft Entra with the SAML option circled
    Choosing SAML as the single sign-on method.
  4. On the SAML setup page, find the SAML Certificates section and copy the App Federation Metadata Url. You will paste it into VeraLab in step 8.
    SAML Certificates section of the Entra SAML setup page with the App Federation Metadata Url field highlighted
    Copy the App Federation Metadata Url from the SAML Certificates section.

Configure SAML in VeraLab

  1. Log in to the VeraLab web application as a user with the Administrator role. If you have an Enterprise Edition license, change the Department to Site Level.
  2. Go to Tools → Settings → Single Sign-on Settings. Select the Enable an additional authentication method checkbox and click Save. The Authentication method is SAML.
    VeraLab Single Sign-on Settings with Enable an additional authentication method checked and SAML selected
    VeraLab Single Sign-on Settings.

    Please note: enabling single sign-on deactivates logging in to the web application via LDAP. All current LDAP accounts are automatically converted to SSO accounts and can only be used through single sign-on. Disabling single sign-on converts all SSO accounts back to LDAP accounts.

  3. On the SAML Authentication Settings page, verify that Hostname and Port match your VeraLab application's FQDN and HTTPS port. For example, if you registered VeraLab on your campus DNS server, they may be veralab.myuniversity.edu and 443. Responses from the authentication server are redirected to this address, so HTTPS support must be enabled.
    VeraLab SAML Authentication Settings with Hostname veralab.myuniversity.edu and Port 443
    Hostname and port on the SAML Authentication Settings page.
  4. Click Import Settings from IdP Metadata, choose Import from URL and paste the App Federation Metadata Url you copied from Entra in step 4. Click Import.
    VeraLab Import Settings from IdP Metadata dialog with Import from URL selected and a login.microsoftonline.com metadata URL pasted
    Importing the Entra metadata from its URL. You can also import from a file or pasted text.
  5. Click Save, leaving the other settings at their defaults.
  6. Back on the Single Sign-on Settings page, under Export metadata from VeraLab SP, click Export metadata and save the VeraLab metadata as an XML file.
    VeraLab Single Sign-on Settings with the Export metadata from VeraLab SP section and Export metadata button highlighted
    Exporting the VeraLab service provider (SP) metadata as an XML file.

Upload the VeraLab Metadata to Entra

  1. Go back to the Microsoft Entra admin center. On the application's SAML-based Sign-on page, click Upload metadata file.
    Entra SAML-based Sign-on page for VeraLab Prod with the Upload metadata file button circled
    Upload metadata file on the SAML-based Sign-on page.
  2. Select the XML file you saved from VeraLab and click Add.
    Entra Upload metadata file panel with the VeraLab SP metadata XML file selected and the Add button
    Selecting the VeraLab metadata XML file.
  3. In the Basic SAML Configuration panel that opens, click Save to complete the metadata upload.
    Entra Basic SAML Configuration panel with the Save button highlighted
    Saving the Basic SAML Configuration.
  4. When Entra asks whether to test single sign-on now, click No, I'll test later.
    Entra prompt to test single sign-on with VeraLab Prod and the No, I'll test later button circled
    Postpone the test until the remaining settings are done.

Set Assignment and Claims

  1. Go to the application's Properties screen, set Assignment required? to No and click Save.
    Entra enterprise application Properties screen with Assignment required set to No and the Save button circled
    Setting Assignment required to No on the Properties screen.
  2. Go to the Single sign-on screen and edit Attributes & Claims. Delete or edit the existing Additional claims so that only these three mappings remain. The Namespace can be left blank.
    Claim nameSource attribute
    emailuser.mail
    first_nameuser.givenname
    last_nameuser.surname
    Entra Additional claims list with email, first_name and last_name mapped to user.mail, user.givenname and user.surname
    The three additional claims VeraLab uses.
    Entra Manage claim form for first_name with an empty Namespace and source attribute user.givenname
    Editing a claim: leave Namespace blank and set the source attribute.

Test Single Sign-On

  1. Test the SSO integration using the Test this application link on the SAML-based Sign-on page.
    Entra SAML-based Sign-on page for VeraLab Prod with the Test this application link highlighted
    Testing the integration with Test this application.

Related: VeraLab LDAP Configuration Guide, VeraLab LDAP integration overview and the VeraLab FAQ. Questions about your setup? Contact VeraLab Support at support@veralab.com.