---
title: "Configure SSO with Azure AD"
canonical: "https://docs.aryaka.com/space/KNOW/1268613131/Configure%20SSO%20with%20Azure%20AD"
format: markdown
---
Aryaka Authentication is a single sign-on (SSO) service that allows our customers to access multiple applications and platforms offered by Aryaka using a single set of credentials. Currently these applications include MyAryaka and the Ticketing Portal. Additionally, Aryaka offers support for customers who use Azure Active Directory (Azure AD) to log in to the MyAryaka portal using their Active Directory credentials. This guide explains how to configure SSO with Azure AD. It includes the following sections: Prerequisites Obtain an Identifier, Reply URL, and Sign on URL for Azure AD in MyAryaka Configure SAML in Azure AD Configure the MyAryaka App in Azure AD Configure Single Sign-on in MyAryaka Upload Metadata to Azure Map Azure Users to Aryaka Users Log in using Azure AD SSO Some of the procedures described in this document are performed in the Microsoft Azure Active Directory administrator interface. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the Azure AD user interface are beyond our control. Refer to the documentation provided by Microsoft to ensure you have the most recent information. Prerequisites MyAryaka account with read/write access Microsoft Azure AD administrator account Obtain an Identifier, Reply URL, and Sign on URL for Azure AD in MyAryaka Complete the procedure in this section to obtain three values—an Identifier, a Reply URL, and a Sign on URL—from MyAryaka. These values are required when configuring SAML in Azure AD in the next section.  To obtain an Identifier, Reply URL, and Sign on URL for Azure AD Log in to MyAryaka. The Home page appears. If you are logged in as a Partner User, the Home page displays the list of customers associated with your account. Do one of the following depending on your user type: (Customer User) Click  Global Settings  >  Access Control  >  SSO . The Single Sign-On (SSO) page appears. (Partner User) Click  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page displays in edit mode. Click the  External IDP  toggle. The configuration fields appear. Click the  Azure AD  icon if it is not already selected. The following fields appear: Identifier (Entity ID) Reply URL Sign on URL The values in these fields are required to configure SAML in Azure AD in the next section. Configure SAML in Azure AD Complete the procedure in this section to configure SAML-based SSO within Azure AD. This procedure results in an application being created in Azure AD called MyAryaka. This application has an associated application tile that appears in your Azure AD dashboard. In the next section, you create a different application tile called MyAryaka Login. To avoid confusion of there being two MyAryaka tiles, the procedure in the Configure the MyAryaka App in Azure AD section begins with instructions for hiding the tile you create in this section.  To configure SAML SSO in Azure AD Log in to Azure AD as an administrator user at  https://manage.windowsazure.com . The Home page appears. Click  Azure Active Directory  in the left navigation pane as shown in the following graphic. Click  Enterprise applications  on the menu that appears. The Enterprise Applications – All Applications page appears. Click  New application . In the Add an Application pane (center), click  Non-gallery application , enter MyAryaka in the Name field (right pane), and then click  Add  (bottom right). After processing the new MyAryaka application, the SSO – Getting Started page appears: Click  Single sign-on  as shown in the previous graphic. The Select a Single Sign-on Method options appear: Click  SAML . The SSO – SAML-based Sign-on page appears: Click the  Edit  icon on the Basic SAML Configuration tile and paste the values copied from the Identifier, Reply URL, and Sign on URL fields in MyAryaka. These values were obtained from MyAryaka during the procedure in the previous section. Save  the changes to the Basic SAML Configuration tile. Click  Download  next to Federation Metadata XML as shown in the previous graphic. The file is downloaded to your local computer or specified location. Share the downloaded Federation Metadata XML file with Aryaka using one of the following options: Upload it to MyAryaka as described in Configure Single Sign-on in MyAryaka. Contact Aryaka customer support at  support@aryaka.com  or  https://info.aryaka.com/contact-us.html . Configure the MyAryaka App in Azure AD This section describes the procedure for creating the MyAryaka application in Azure AD, which results in the creation of the  MyAryaka Login  application tile. The procedure begins by hiding the  MyAryaka  application tile created in the previous section to avoid possible confusion. The SAML SSO configuration associated with the original tile is still referenced after the tile is hidden. To create the MyAryaka application entry in Azure AD Ensure you are logged in to Azure AD as an administrator user. Hide the existing MyAryaka application tile that you created for the SAML SSO: Go to the Azure AD Home page, click  Azure Active Directory  in the left navigation pane, and then select  Enterprise Applications  from the pop-up menu. The Enterprise Applications page appears. Click  All Applications  in the left navigation pane. The Enterprise Applications | All Applications page appears:  Enter MyAryaka (or whatever name you entered in Name field in step 5 of the previous procedure) in the Search field as shown in the previous graphic. The search results display the MyAryaka Properties page: Click  Properties  in the left navigation pane, click  No  next to the Visible to Users option, and then click  Save . The SAML SSO configuration is updated to hide the MyAryaka application tile but retain the other properties. Return to the Enterprise Applications page. You can use the left navigation pane or the path at the top of the page: Click  New Application : The Add an Application page appears. Click  Non-gallery application . The Add Your Own Application page appears: Enter MyAryaka Login in the Name field, then click  Add . After the application is created, the MyAryaka Login | Overview page appears: Click  Assign users and groups . The MyAryaka Login | Users and Groups page appears: Click  Add User , then select the groups or individual users in your organization that need access to MyAryaka. Click  Overview  in the left navigation pane, then click  Set up Single Sign On . The MyAryaka Login | Single Sign-on page appears.  Select the  Linked  option. The MyAryaka Login | Linked Sign-on page appears. Enter  https://my.aryaka.com/IdpLoginForm  in the Sign on URL field, then click  Save . Click  Properties  in the left navigation pane, upload the Aryaka logo (optimum size for the logo is 215 x 215 pixels), and then click  Save .  The MyAryaka Login application configuration is complete. Users that were assigned access can see the MyAryaka Login application tile in the Azure AD portal: Configure Single Sign-on in MyAryaka Log in to MyAryaka. The Home page appears. If you are logged in as a Partner User, the Home page displays the list of customers associated with your account. Do one of the following depending on your user type: (Customer User) Click  Global Settings  >  Access Control  >  SSO . The Single Sign-On (SSO) page appears. (Partner User) Click  Access Control  >  Partner SSO . The Single Sign-On (SSO) page appears in read-only mode. Click the  Edit  icon. The page appears in edit mode. Click the  External IDP  toggle. The SSO configuration fields appear. Click  Azure AD . The Azure AD-specific configuration field appears. Note that the MyAryaka Authentication option is enabled by default. (Optional) Click  No  in the Enable MyAryaka Authentication field to disable the MyAryaka Authentication service. Click  Browse , then navigate to the Azure IDP Federation Metadata XML file (Federation Metadata) that you downloaded from the Azure administration portal. Click the  Submit  icon. The uploaded file is automatically processed, and the Aryaka (SP) Entity ID field appears. Click the  Download  icon next to the Aryaka (SP) Entity ID field to download the SP Metadata file, then upload it to the Azure AD portal as described in the next section. Upload the Metadata SP File to Azure AD Log in to Azure AD as an administrator user at  https://manage.windowsazure.com . The Home page appears. Open the SAML-based Sign-on page as shown in the following graphic: Click  Upload metadata file  to upload the file downloaded from MyAryaka (as described in step 10 of Configure SAML in Azure AD) or received from Aryaka Support. The Upload Metadata File fields appear. Click the  Folder icon  next to the Select a File field, navigate to the metadata file, and then click  Add . If the metadata file uploads successfully, SSO setup is complete. Continue to the next section. If this step fails, contact Aryaka Support. Map Azure AD Users to Aryaka Users This user mapping step is not required if a user's Azure AD user name is the same as his or her MyAryaka user name (the email address used to log in to MyAryaka). If the email addresses differ, the user's account ID must be configured in MyAryaka to match the corresponding Azure AD account. Users' IDs can be added or modified in the MyAryaka User Management section as follows. To modify user accounts in MyAryaka Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane, then click  Users  in the Access Control tile. The Users page appears. It lists all users configured in MyAryaka and their email address used to access MyAryaka. Click the row of the user you want to modify. The user's details page appears. Click the  Edit  icon. The page appears in edit mode and includes additional fields. Set the SSO ID Same as Email field to  No , and then enter your Azure ID login ID (the user name you use to log in to Azure AD) in the SSO ID field that appears. Click  Submit . A change request is sent to Aryaka support.    Repeat this procedure for all users configured in MyAryaka whose Azure AD login email address differs from their MyAryaka login email address. Log in using Azure AD SSO The SSO log in process differs slightly depending on whether the user's organization has configured  both  authentication systems (that is, Aryaka's and Azure's), or only Azure's: If the user's organization has configured  both  authentication systems, the following workflow occurs the first time users click the MyAryaka Login tile in their Azure portal: User is prompted for his or her MyAryaka username, then clicks Continue. The next window offers the option to Sign in with Azure. Note that if this user has logged in using the direct MyAryaka URL previously, he or she is  not  prompted for the MyAryaka username. User selects the Sign in with Azure option to complete the single sign-on and display the MyAryaka Home page. On subsequent visits, users do not need to provide the MyAryaka username, when they select the Sign in with Azure option, they go directly to MyAryaka Home page. If the user's organization has configured  only Azure  authentication, the following workflow occurs the first time users click the MyAryaka Login tile in their Azure portal: User is prompted to enter his or her MyAryaka username, then clicks Continue. The MyAryaka Home page appears. Note that if this user has logged in using the direct MyAryaka URL previously, he or she is  not  prompted for the MyAryaka username. On subsequent visits, when the user clicks on MyAryaka application tile in Azure, the MyAryaka Home page appears. If users clear their browser cookies, they must reenter their MyAryaka username the first time after clicking the MyAryaka tile in the Azure portal. Additional Resources Contact Aryaka support at support@aryaka.com if you need any help. You can also contact us at  https://info.aryaka.com/contact-us.html In this topic Related topics Configure SSO Log in to MyAryaka using SSO