Identity Provider: Azure Active Directory (AAD)
AAD User permission: Have one of the following roles in Azure:
- Global Administrator
- Cloud Application Administrator
- Application Administrator
1. User who has the proper role/permission in Identity Provider to create applications and assign people to applications.
2. User who has completed the registration in https://www.enterprisedb.com/accounts/register/biganimal and can login BigAnimal portal (Switch to the correct organization if applicable)
3. Verify a domain. This may need to engage the customer's IT team to add TXT record. Steps can refer to doc(have details steps): Add a domain
0. Login to BigAnimal portal via EDB Account, go to 'Settings' -> ' Identity Provider' by clicking Profile (right upper corner)
1. Log into the Azure Active Directory Admin Center, go to Enterprise Applications > New application
2. Create your own application, enter a name for your application, then select Integrate any other application you don’t find in the gallery (Non-gallery)
3. After the application is created, from the left panel, select Single sign-on, select SAML
4. Edit Basic SAML Configuration, copy the Audience URI from BigAnimal 'Identity Provider' page: Connection Info to Identifier (Entity ID), copy Assertion Consumer Service URL to Reply URL
6. Download the Certificate with Base64 format in SAML Certificates section
7. Copy Login URL in section 4 Set up <You application name >
8. Click Properties in the left pane and select if Assignment is Required or not
9. Login to BigAnimal portal, go to 'Settings' -> ' Identity Provider' , scroll down to 3 SAML Settings
- Single Sign-On URL - > URL copied in step 7
- Identity Provider Signature Certificate -> Certificate in step 6
- Request Binding - > HTTP-POST
- Response Signature Algorithm -> sha256 or rsa-sha1
10. Click 'Test Connection' and login with your Azure account.
11. If Test Connection is successful, then you are good to click 'Sign into BigAnimal'
Please note, input your email address in the box under Sign in to your BigAnimal account as the below screenshot. (Don't click Sign in for Azure Marketplace users)
Possible error 1
If you get the below block error AADSTS50105, it's caused by the Assignment Requirement in step 8 is Yes. But you/the users are not assigned to the application specifically.
To resolve the error, go to Users and Groups at the left pane and Add User/group
Add the specific users or groups and then click 'Assign' and go back 'Test Connection' in step 10 again.
Possible error 2
If you got the error AADSTS50020 like "the user does not exist in tenant", then it's caused by browser cache then a wrong user was logged in Azure portal.
To resolve this issue, you can open a Private window or clear your browser cache and try 'Test Connection' in Step 10 again.