Requirements
- Advanced Authentication + User Management
Set up single sign-on (SAML) for Robin with the pre-configured SAML app in Azure. If the pre-configured app does not work for you, connect Azure as a custom integration. Follow the steps in Enabling single sign-on via SAML 2.0.
-
In Azure Active Directory, go to Enterprise Applications > New Application. Search for the Robin app, then select Create.
-
In the Robin app in Azure, select Single sign-on. Scroll down and download the Federation Metadata XML file. You need this file in step 5.
As a Robin admin, open the Robin web dashboard and go to Manage > Integrations. Scroll down to the "Authentication methods" section to find the SAML SSO option.
-
Select + Add to open the configuration window.
-
Select Import Metadata and import the XML file you downloaded from Azure in step 2.
Select Advanced Options (see the image above) to choose the auth contexts.
-
In the Auth Context menu, select Password Protected Transport & Windows.
Common errors
If you see this error when you sign in, check that the auth contexts in Robin match the image above:
“AADSTS750161:Allowed SAML authentication request's NameIDPolicy formats are: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress,urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified,urn:oasis:names:tc:SAML:2.0:nameid-format:persistent,urn:oasis:names:tc:SAML:2.0:nameid-format:transient.”
If you see "AADSTS75011: Authentication method used doesn't match the requested authentication method", uncheck all the options in the Auth Context menu. This lets the IdP negotiate the assertion format.