This document describes how to set up the Azure Active Directory (AAD) Third-Party Login.
In general, the users created in AAD and added to the specific Enterprise Application can be used for Single Sign On on DragOnce.
To complete the account synchronization, there are some pre-conditions.
AAD must be used
Enterprise Application can be added to AAD
Contact us for infrastructure and database setup (e.g. define Subscriber Identifier)
Add an Enterprise Application
Login to Azure Portal
Open the “Azure Active Directory”
Select “Enterprise applications” on the left menu.
Create a new application.
a. Select “Non-gallery application”.
b. Input a desired name
5. Create the application
Please be aware that the interface may have differences due to the update of AAD, check Microsoft support if needed.
On the left menu, select “Single sign-on”
a. Choose “SAML” as the single sign-on method
b. In section 1 Basic SAML Configuration of AAD, you will need to enter the below information provided on the DragOnce platform
i. Identifier (Entity ID)
ii. Reply URL (Assertion Consumer Service URL)
iii. Sign on URL
iv. Logout URL
2. Login to DragOnce and go into Admin Panel
a. On the left menu, select “Third-Party Login”
b. If the Identifier (Entity ID) is empty, you may copy the Subscriber Identifier on the top right corner as the Identifier (Entity ID) and Apply the settings
c. Copy the below 4 info on screen and paste to AAD on the above step
i. Identifier (Entity ID)
ii. Reply URL (Assertion Consumer Service URL)
iii. Sign on URL
iv. Logout URL
d. Click “Save” in AAD after copied
3. In section 3 SAML Signing Certificate of AAD, download the certificate named “Certificate (Base64)”.
4. Upload the downloaded certificate to DragOnce
5. In section 4 of AAD, copy and paste the below settings to DragOnce
a. Login URL
b. Azure AD Identifier
c. Logout URL
6. Click “Apply” to save the settings
Can I change the Subscriber Identifier?
Subscriber Identifier cannot be changed after setup.
Why can't I find the Third-Party Login settings in DragOnce?
The Third-Party Login is a paid enterprise feature on request, please contact us if you want to enable it.