Skip to main content
< All Topics
Print

Azure Entra ID SSO (Single Sign On)

You can use Azure Entra ID SSO (Single Sign On) with LeaveWizard to make it easier for users to sign in.

However, Microsoft has suspended new marketplace submissions (opens in new tab), so currently you have to configure SSO manually on Azure Entra ID as we cannot add LeaveWizard and make it available in the gallery.

Create LeaveWizard App On Azure

On the Microsoft Azure portal, navigate to the ‘Enterprise applications’ service. Either select ‘Enterprise Applications’ from the Azure services list on the main page or, if it does not list it, select ‘More services’ and select it on the ‘All services’ page from the ‘Identity’ category.

A screenshot showing the 'Enterprise Applications' and 'More services' icons on the Azure services list on the Azure main page.

Create a new application by clicking ‘+ New application’ at the top of the page and then ‘+ Create your own application’ on the next ‘Entra Gallery’ page. Enter a suitable name for the app, like LeaveWizard, and select the ‘Integrate any other application you don’t find in the gallery (Non-gallery)’ option. Click the ‘Create’ button.

A screenshot showing the page to create a new application that does not exist in the gallery.

Setup SAML SSO

Once you have created the app, it will take you to the app overview page.

A screenshot showing the application overview page and the links to set up Single Sign On (SSO).

In the ‘Getting Started’ section, click the ‘Get started’ link in the ‘Set up single sign on’ box or you can select ‘Manage’ and then ‘Single sign-on’ from the menu on the left-hand side of the page. Select the ‘SAML’ box.

A screenshot showing the SAML-based Sign-on configuration page with the two sections that need to be updated.

In section 1, ‘Basic SAML Configuration’, click the Edit icon and enter the following.

Identifier (Entity ID): https://identity.leavewizard.com/Saml2

Reply URL (Assertion Consumer Service URL): https://identity.leavewizard.com/Saml2/Acs

Click ‘Save’

In section 2, ‘Attributes & Claims’, click the Edit icon and then click ‘+ Add new claim’ and enter the following.

Name: userid

Source attribute: user.objectid

Click ‘Save’. Close the Attributes and Claims section by clicking the ‘X’ icon.

Configure SAML authentication On LeaveWizard

To use SSO, you need to configure SAML authentication on LeaveWizard.

Keep your Azure browser page open. Now, sign into LeaveWizard as an administrator and select company settings from the configuration option on the main menu. Navigate to the authentication section and click the ‘Configure’ button.

A screenshot showing the ‘Configure’ button on the 'Authentication' section of the LeaveWizard 'Company settings' page.

On Azure, using the link, copy ‘Microsoft Entra identifier’ from section 4 and paste it into the ‘Issuer Name’ field of the ‘Configure SAML authentication’ section of LeaveWizard.

On Azure, using the link, copy ‘App Federation Metadata Url’ from section 3 and paste it into the ‘Metadata Location’ field of the ‘Configure SAML authentication’ section of LeaveWizard.

A screenshot showing the 'Issuer Name' and 'Metadata Location' fields on the 'Configure SAML authentication' section of LeaveWizard.

Click ‘Submit’ to complete the configuration.

Login And Test

If you want to test SSO, you will need to add a user to users and groups from the menu on the left-hand side of the page. Select ‘Manage’ and the ‘Users and Groups’ option.

A screenshot showing the empty LeaveWizard app manage user and groups page.

When users first log in using SSO, please ask them to follow the instruction in our Login And Passwords knowledge base article specific to their role on LeaveWizard.

If you would like to configure automatic user provisioning, then please read our Azure Entra ID SCIM User Provisioning article.

Table of Contents