Set up single sign-on with Azure Active Directory

Requirements

  • Advanced Authentication + User Management

Set up single sign-on (SAML) for Robin with the pre-configured SAML app in Azure. If the pre-configured app does not work for you, connect Azure as a custom integration. Follow the steps in Enabling single sign-on via SAML 2.0.

  1. In Azure Active Directory, go to Enterprise Applications > New Application. Search for the Robin app, then select Create.

    2022-10-27_13-59-32.png

  2. In the Robin app in Azure, select Single sign-on. Scroll down and download the Federation Metadata XML file. You need this file in step 5.

    SSO_Azure_direct._.jpg

  3. As a Robin admin, open the Robin web dashboard and go to Manage > Integrations. Scroll down to the "Authentication methods" section to find the SAML SSO option.

  4. Select + Add to open the configuration window.

    Add_SAML_btn.jpg

  5. Select Import Metadata and import the XML file you downloaded from Azure in step 2.

    2022-10-27_06-45-10.png

  6. Select Advanced Options (see the image above) to choose the auth contexts.

  7. In the Auth Context menu, select Password Protected Transport & Windows.

    2022-10-27_06-51-43.png

Common errors

If you see this error when you sign in, check that the auth contexts in Robin match the image above:

“AADSTS750161:Allowed SAML authentication request's NameIDPolicy formats are: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress,urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified,urn:oasis:names:tc:SAML:2.0:nameid-format:persistent,urn:oasis:names:tc:SAML:2.0:nameid-format:transient.”

2022-10-27_06-58-47.png

If you see "AADSTS75011: Authentication method used doesn't match the requested authentication method", uncheck all the options in the Auth Context menu. This lets the IdP negotiate the assertion format.

Articles in this section

Was this article helpful?
1 out of 6 found this helpful
Share