Microsoft Azure SSO SAML Integration



SimpleMDM integrates with Microsoft Azure using the Security Assertion Markup Language (SAML) standard. This guide will explain how to designate an Azure account as a trusted identity provider (IdP) for authenticating administrators of your SimpleMDM account.

As the Microsoft Azure user interface may change, this guide has been written to provide a general process for getting up and running.

In SimpleMDM:

  1. Navigate to Settings > Users.
  2. Click the 'Settings' tab.
  3. Under the 'Single Sign On with SAML' section, select "Yes" to enable SAML.
  4. In the 'Identity Provider Information' section, find the Short Name field and enter your company name (must be one word - no spaces or special characters).
  5. Click 'Save'. The fields under 'SimpleMDM Information' will automatically populate.

In Azure:

  1. Log into Microsoft Azure https://portal.azure.com/ 
  2. Navigate to Enterprise Applications.
  3. Click 'New application'.
  4. Select 'Create your own application'.
  5. Enter a name for the application and click 'Create'
  6. Under 'Getting Started', select '2. Set up single sign on'.
  7. Select 'SAML'.
  8. Click 'Edit' on the 'Basic SAML Configuration' section
  9. Copy the value in the Audience field in SimpleMDM and enter it in the Identifier (Entity ID) field in the Azure settings.
  10. Copy the 'SimpleMDM SAML Consumer URL' from SimpleMDM and enter it in the 'Reply URL' field in Azure.
  11. Copy the 'SimpleMDM Single Logout URL' from SimpleMDM and enter it in the 'Logout URL' field in Azure.
  12. Click 'Save' and close the 'Basic SAML Configuration' window

Back in SimpleMDM:

  1. In Azure scroll down to the 'SAML Certificates' section.
  2. Copy the 'Thumbprint' value from Azure and enter it in the 'X.509 fingerprint or certificate' field in SimpleMDM.
  3. In Azure scroll down to the 'Set up SimpleMDM-SSO-Login' section.
  4. Copy the 'Login URL' value from Azure and enter it in the 'Endpoint URL' field in SimpleMDM.
  5. Copy the 'Logout URL' value from Azure and enter it in 'Single Logout URL' field in SimpleMDM.
  6. Save the settings.

Once complete, test the connection in the Azure settings to ensure the setup was successful.

Still have a question or want to share what you have learned? Visit our Community Discord to get help and collaborate with others.