Configuring SAML SSO: Microsoft Azure

1 min read

Let your team sign in to FCSky with their existing Microsoft Azure credentials by configuring SAML single sign-on between Azure AD and FranConnect.

Important

This SSO functionality supports Just-in-Time (JiT) provisioning only. There is no support for Ahead-of-Time (AoT) provisioning.

Before you begin

You need admin access to your FCSky platform, admin access to cloud-based Azure Active Directory with the Application Administrator role, and admin access to on-premises Active Directory Users and Computers. Work with both tabs open — you'll copy values between them.

Step-by-Step Instructions

Follow these steps to configuring SAML SSO: Microsoft Azure

1

Start a SAML Service Provider in FCSky

Open Configure Single Sign-On from other websites, click Add New SAML Service Provider, set Authentication Type to Service Provider Initiated (SP-Init) and copy the Assertion Consumer Service (ACS) URL.

Admin › Configuration › Single Sign On › Configure Single Sign-On from other websites

Single Sign On section in FCSky admin settings

Fig 1 — Configure Single Sign-On from other websites.
Important

Keep the ACS URL handy — it looks like https://<YourPlatformUrl>/fc/saml/acs/McKJPeVcGExi98J/. Leave this page open; you'll come back to finish it.

2

Create the application in Azure AD

At entra.microsoft.com, go to Applications › Enterprise applications, click New application › Create your own application, name it and choose Integrate any other application you don't find in the gallery (Non-gallery), then click Create.

Azure AD › Applications › Enterprise applications › New application

Create your own application dialog with the non-gallery option selected

Fig 2 — Name the app and pick the non-gallery option.
Tip

Use a name specific to your platform rather than a generic one.

3

Fill in the Basic SAML Configuration

Go to Manage › Single sign-on, choose the SAML method, click Edit on Basic SAML Configuration and add both values, then Save.

Azure AD › Manage › Single sign-on › SAML
Identifier (Entity ID) https://<YourPlatformUrl>/fc/
Reply URL (ACS URL) The ACS URL you copied in Step 1

Basic SAML Configuration with identifier and reply URL filled in

Fig 3 — Basic SAML Configuration.
4

Get the certificate and Login URL

Under SAML Certificates, download the Certificate (Base64), then copy the Login URL from the Set up …SSO section.

SAML Certificates section with the Base64 certificate download link

Fig 4 — Download the Certificate (Base64).

Set up SSO section showing the Login URL

Fig 5 — Copy the Login URL.
5

Finish the SAML provider in FCSky

Back on the FCSky tab, complete the remaining fields and click Continue.

Name A unique name for the connector
Identity Provider Single Sign-On URL The Azure Login URL from Step 4
Identity Provider Logout/Redirect URL https://<YourPlatformUrl>/fc/control/logout
Protocol Binding for SAML Request HTTP-POST
Request Lack Time (In Minutes) As appropriate for your environment
X.509 Signing Certificate Upload the Base64 certificate from Step 4
Is Default SAML SSO? Whether SSO becomes the default/only login method
Is Provision User? Whether accounts are created on first SSO login

Completed SAML service provider form in FCSky

Fig 6 — The completed SAML service provider.
Tip

Leave Is Default SAML SSO? unchecked to keep native FCSky login available alongside SSO. The SAML Attributes tab lists the field mappings — this guide keeps the default names.

6

Create SAML Groups (only if provisioning users)

Open SAML Groups, click Add SAML Group, name it, choose the User Type, click Save, then use the action menu to Associate With Roles and pick the roles new users should get.

Admin › Users › SAML Groups
FC User Type WM Role Type
Corporate World Manager
Divisional National Manager
Regional Area Manager
Franchise General Manager, Store Manager, Employee

SAML group with associated roles selected

Fig 7 — The roles you associate here are assigned to provisioned users.
Important

Skip this step if you left Is Provision User? unchecked — the SAML Groups link only appears once at least one provider has it checked. Repeat for every group you need.

7

Edit the Azure claims

In Attributes & Claims, click Edit, rename the auto-generated claims and add the ones your connector requires — clearing the Namespace and setting Name format to Unspecified on each.

Claim name Source attribute
EmailID (rename emailaddress) user.mail
FirstName (rename givenname) user.givenname
LastName (rename surname) user.surname
name Delete this claim
LoginIDUsername Any attribute, e.g. user.employeeid — becomes the username
GroupName Any attribute, e.g. user.jobtitle — must exactly match a SAML group name
Country Transformation: RegexReplace on user.country
State user.state
City user.city
Phone1 user.telephonenumber or user.mobilephone
Language user.preferredlanguage
AreaRegion An extension attribute — Area/Region users only
FranchiseUserType An extension attribute — Location users only; accepts "Owner" or "Employee"
FranchiseIDLocationName An extension attribute — must match a Location name exactly
Division user.officelocation — Divisional users only
WorldManagerCountry Transformation: RegexReplace on user.country
WorldManagerAccountGroup An extension attribute — any WM Account Group name
WorldManagerAccountGroupType An extension attribute — accepts "world-view" or "country-view"
WorldManagerEmployeeOnly An extension attribute — accepts "Yes" or "No"

Completed Attributes and Claims list in Azure AD

Fig 8 — The finished claims list.
Important

Claim names must exactly match the SAML Attributes tab of your FCSky connector. Azure abbreviates user.country to a country code (Australia → AU) and FCSky expects the full name, which is why Country uses a RegexReplace transformation — adjust the pattern for your own countries. Full state names are required too. The value under Required claim cannot be removed but is ignored.

8

Assign users and groups to the app

Go to Manage › Users and groups, click Add user/group, search for and select each user or group, click Select, then Assign.

Azure AD › Manage › Users and groups › Add user/group

Selecting users to assign to the enterprise application

Fig 9 — Select every user or group that needs access.
Need help?

For assistance configuring SAML SSO, contact helpdesk@franconnect.com.

Was this article helpful?
Your feedback helps us improve our documentation.