Let your team sign in to FCSky with their existing Microsoft Azure credentials by configuring SAML single sign-on between Azure AD and FranConnect.
This SSO functionality supports Just-in-Time (JiT) provisioning only. There is no support for Ahead-of-Time (AoT) provisioning.
You need admin access to your FCSky platform, admin access to cloud-based Azure Active Directory with the Application Administrator role, and admin access to on-premises Active Directory Users and Computers. Work with both tabs open — you'll copy values between them.
Step-by-Step Instructions
Follow these steps to configuring SAML SSO: Microsoft Azure
Start a SAML Service Provider in FCSky
Open Configure Single Sign-On from other websites, click Add New SAML Service Provider, set Authentication Type to Service Provider Initiated (SP-Init) and copy the Assertion Consumer Service (ACS) URL.
Keep the ACS URL handy — it looks like
https://<YourPlatformUrl>/fc/saml/acs/McKJPeVcGExi98J/.
Leave this page open; you'll come back to finish it.
Create the application in Azure AD
At entra.microsoft.com, go to Applications › Enterprise applications, click New application › Create your own application, name it and choose Integrate any other application you don't find in the gallery (Non-gallery), then click Create.
Use a name specific to your platform rather than a generic one.
Fill in the Basic SAML Configuration
Go to Manage › Single sign-on, choose the SAML method, click Edit on Basic SAML Configuration and add both values, then Save.
| Identifier (Entity ID) |
https://<YourPlatformUrl>/fc/
|
| Reply URL (ACS URL) | The ACS URL you copied in Step 1 |
Get the certificate and Login URL
Under SAML Certificates, download the Certificate (Base64), then copy the Login URL from the Set up …SSO section.
Finish the SAML provider in FCSky
Back on the FCSky tab, complete the remaining fields and click Continue.
| Name | A unique name for the connector |
| Identity Provider Single Sign-On URL | The Azure Login URL from Step 4 |
| Identity Provider Logout/Redirect URL |
https://<YourPlatformUrl>/fc/control/logout
|
| Protocol Binding for SAML Request | HTTP-POST |
| Request Lack Time (In Minutes) | As appropriate for your environment |
| X.509 Signing Certificate | Upload the Base64 certificate from Step 4 |
| Is Default SAML SSO? | Whether SSO becomes the default/only login method |
| Is Provision User? | Whether accounts are created on first SSO login |
Leave Is Default SAML SSO? unchecked to keep native FCSky login available alongside SSO. The SAML Attributes tab lists the field mappings — this guide keeps the default names.
Create SAML Groups (only if provisioning users)
Open SAML Groups, click Add SAML Group, name it, choose the User Type, click Save, then use the action menu to Associate With Roles and pick the roles new users should get.
| FC User Type | WM Role Type |
|---|---|
| Corporate | World Manager |
| Divisional | National Manager |
| Regional | Area Manager |
| Franchise | General Manager, Store Manager, Employee |
Skip this step if you left Is Provision User? unchecked — the SAML Groups link only appears once at least one provider has it checked. Repeat for every group you need.
Edit the Azure claims
In Attributes & Claims, click Edit, rename the auto-generated claims and add the ones your connector requires — clearing the Namespace and setting Name format to Unspecified on each.
| Claim name | Source attribute |
|---|---|
EmailID (rename emailaddress)
|
user.mail
|
FirstName (rename givenname)
|
user.givenname
|
LastName (rename surname)
|
user.surname
|
name
|
Delete this claim |
LoginIDUsername
|
Any attribute, e.g. user.employeeid
— becomes the
username
|
GroupName
|
Any attribute, e.g. user.jobtitle
— must exactly
match a SAML group name
|
Country
|
Transformation: RegexReplace on user.country
|
State
|
user.state
|
City
|
user.city
|
Phone1
|
user.telephonenumber or
user.mobilephone
|
Language
|
user.preferredlanguage
|
AreaRegion
|
An extension attribute — Area/Region users only |
FranchiseUserType
|
An extension attribute — Location users only; accepts "Owner" or "Employee" |
FranchiseIDLocationName
|
An extension attribute — must match a Location name exactly |
Division
|
user.officelocation — Divisional
users only
|
WorldManagerCountry
|
Transformation: RegexReplace on user.country
|
WorldManagerAccountGroup
|
An extension attribute — any WM Account Group name |
WorldManagerAccountGroupType
|
An extension attribute — accepts "world-view" or "country-view" |
WorldManagerEmployeeOnly
|
An extension attribute — accepts "Yes" or "No" |
Claim names must exactly match the SAML Attributes
tab of
your FCSky connector. Azure abbreviates user.country
to a country
code (Australia → AU) and FCSky expects the full name, which
is why Country
uses a RegexReplace transformation — adjust the pattern for
your own countries.
Full state names are required too. The value under
Required claim cannot be removed but is
ignored.
Assign users and groups to the app
Go to Manage › Users and groups, click Add user/group, search for and select each user or group, click Select, then Assign.
For assistance configuring SAML SSO, contact helpdesk@franconnect.com.