KB Article #191960

Amplify Fusion Single Sign On using Microsoft Entra ID

Amplify Fusion Single Sign On using Microsoft Entra ID

This guide will describe how to configure Amplify Fusion to enable log on via Single Sign-On (SSO) using Microsoft Entra ID. The guide was created using Amplify Fusion 1.11.2

The basic steps are:

  1. Configure a new SAML 2.0 application
  2. Configure Single Sign On in the Amplify Fusion Manager module by importing the SAML Metadata XML file
  3. Test the SSO Integration as Follows


Configure an Enterprise Application in Microsoft Entra

  1. Navigate to the Microsoft Entra admin center at entra.microsoft.com
  2. Select Enterprise apps and then click New application
    image815a54004b4b7de8331d04705b3da984_000.png

  3. Click Create your own, fill in the name, for example Amplify Fusion, choose Integrate any other application you don't find in the gallery (Non-gallery) and click Create
    image1867d9b075d49682c9daca227be304d1_000.png

  4. Click on 2. Set up single sign on
    image5228685afa89f20e8950e9dc1fca2c74_000.png

  5. Choose SAML as the sign-on method
    image59ad6fd71b14e1cf13399aa3966ece16_000.png
  6. Click on Edit in the Basic SAML Configuration section to fill in the required informationimage0b2404a4b66cf4cc470c58898bfd1789_000.png
  7. Click Add identifier and fill in https://tenant.domain/api/saml2/service-provider-metadata/default, then click Add reply URL and fill in

  8. After clicking save your configuration should look like below
    image0fbc88e4a37e779af60ec859a1960fc0_000.png
  9. Download the Federation Metadata XML, we’ll import it into Fusion later
    imagef5ae6adaabbca9f766529163b72a4694_000.png
  10. Go back to the Overview page and click Assign users and groups and select the users or groups you wish to grant access to the applicationimage82aa6694e120070b7aa3fca596bd7de4_000.png



Configure Amplify Fusion Single Sign On

  1. Click on Manager -> Single Sign On
    image4e76b243f8164b2b18850edd0244f65e_000.png
  2. Enter a name and optionally a description, then click Choose File and select the federation metadata XML file you downloaded earlier, this will populate several of the form fields
    image42ae69faf0d8a08a9e5387cbd4abc62c_000.png
  3. Scroll down to the Attribute Mapping section and enter the following in the Attribute Name part of the fields
  4. Enable Provision New Users and set the Default Roles and Teams
    image89df4d39e7ee459b133f203c6c3c0af5_000.png


Sign on to Amplify Integration using SSO

  1. At this point single sign on may be tested. Sign out of Amplify Fusion and click on the Login SSO button
    imagef4a702e1374ff1804752fd4d40723c07_000.png
  2. You will be redirected to the Microsoft Sign in page to enter your credentials
    imagee586ee1360250beb0ba45e2acfd83134_000.png
  3. Complete the authentication by fulfilling the MFA criteria, in the example below you must enter the number in Microsoft Authenticator
    image99603834ff4bd05e9d12c48b72c5ef75_000.png
  4. You will now be logged in Amplify Fusion. If the user does not already exist, it will be created with the default roles and teams from single sign page as previously configured
    image9a78ad0bbb3d45b2b1a61a2f67ed3c5f_000.png
  5. You can check the roles and teams by clicking the account name in the top right corner and clicking settingsimagee57baa63be2ddfb2b1f5dbb6d9790414_000.png
  6. User account should also be visible to super administratorsimage5291f310aa7b9bd9adb5979ce2d6dc3c_000.png