by Avihai Cohen
Intro
Ask Gaviti support team for some necessary SSO configuration before you begin.
In this tutorial we will use this configuration for example:
Ask for support to provide you these two URLs.
Reply URL (Assertion Consumer Service URL):
US Server
US Server
Create a new enterprise application.
Open Microsoft Azure Enterprise applications click here…
Click on “+ New application”
Click on “+ Create your own application”
Input the name: “Gaviti” and click on “Create” (It can take a few seconds…)
Click on “Manage” → “Single sign-on” on the left side menu
Click on “SAML” and start filling 4 sections as described.
1st section (Basic SAML Configuration):
Click on “Edit” to edit the Basic SAML Configuration.
Click on “Add identifier” and enter the Identifier: “gaviti” into the new empty row.
Click on “Add reply URL” and enter the reply URL into the new empty row (you received it from Gaviti support). e.g. “https://api.gaviti.com/v2/auth/sso/callbackUrl?securityPolicyId=[uuidv4]”
Enter the Sign on URL “Assertion Consumer Service URL” (you received it from Gaviti support). e.g. “https://app.gaviti.com/login/sso?securityPolicyId=[uuidv4]”
Click on “Save”
Click on “X” to close the right side menu after it is successfully saved.
Note: Sometimes if its not works but all definition are correct need to delete: Sign on URL (just leave empty)
2nd section (Attributes & Claims):
Click on “Edit” to edit the Attributes & Claims.
Click on “Unique User Identifier (Name ID)”.
Change the Source attribute to “user.mail”.
Click on “Save”.
Click on “X” to go back to the SAML-based Sign-on page.
3rd section (SAML Certificates): Download the Certificate (Base64) and save it for next steps.
4th section (Set up Gaviti): Copy the “Microsoft Entra Identifier” and save it for next steps.
The final result should look like this:
Get the user access URL.
At the same main screen in Azure.
Click on “Manage” → “Properties” in the left side menu.
Copy the User access URL and save it for next steps.
Add users/groups to the enterprise application.
Click on “Manage” → “Users and groups” in the left side menu.
Click on “Add user/group”.
Click on “None Selected”.
Select the users/groups that you want to give access to.
Click “Select”.
Click “Assign”.
Final required details
The Gaviti supports should receive from you all these collected details:
Certificate file (Base64).
Microsoft Entra Identifier.
User access URL.
