Azure AD SSO Setup
Parameters Needed
Criteria Provided Parameters
- Entity ID (Audience URI)
- urn:amazon:cognito:sp:us-east-1_tkdHRnjPD
- Assertion Consumer Service URL
- https://hireselect.auth.us-east-1.amazoncognito.com/saml2/idpresponse
- First-Time Sign-On URL/BookMark:
- Once Soft-Enabled, Criteria CSM to provide customer with following link to include their unique company account ID. Customer must login via this link and not through their service provider):
- https://hireselect.criteriacorp.com/?companyAccountId=<companyAccountId>
- Our Required SAML Attributes
- First Name
- Last Name
- Email Address
- Optional SAML Attribute
- Job Title
- Idp Immutable Global Unique Identifier (Varies by Idp)
What we need from you
- Federation Metadata Document endpoint URL (Can also be an XML Document but URL preferred)
Step-By-Step Guide
Create an Azure SAML Application
- Visit the Azure Active Directory Page on your Azure Portal
- In Active Directory Menu Blade click on Enterprise Applications
- Select New Application at the top left
- Select Non-gallery application and type in HireSelect as the application name
- Edit the SSO Configuration
- On the App Overview screen select Set up single sign on
- Select SAML
- Click to Edit the Basic SAML Configuration
- For the Identifier (Entity ID) field enter urn:amazon:cognito:sp:us-east-1_tkdHRnjPD
- For the Reply URL (Assertion Consumer Service URL) field enter https://hireselect.auth.us-east-1.amazoncognito.com/saml2/idpresponse
- For the Sign on URL enter https://hireselect.criteriacorp.com/SSO?companyAccountId=<companyAccountId>
- Click Save
- Click to Edit the User Attributes & Claims
- Change the name identifier format to Persistent and the Source Attribute to user.objectid
- Click Save
- Edit the http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress claim value to user.userprincipalname
- Add another claim with the name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/identifier And set the value to user.objectid
Download the SAML Metadata URL
- On the Single Sign-On Screen copy the App Federation Metadata URL and send this to our Support Team.
Next Steps
Our team will update your Criteria account and advise once we are ready to begin testing the integration. For next steps, please continue to our SSO How-to Guide.