Configure Settings in SureMDM Console (Azure)


1.  Navigate to SureMDM Web Console > Settings (icon located at the top right of the screen) > Account Settings > SAML Single Sign-On.

2.  Configure Single Sign-On settings for Azure AD.

     

Settings

Description

Enable Single Sign-On

Select this option to allow configuring Single Sign-On settings.

SSO Type

Select Azure AD.

Service Identifier

Enter the Service Identifier

This value is present under EntityDescriptor tag, entityID property of metadata XML file. See step no.7, Configure settings in Azure AD server

For example: https://sts.windows.net/f7ecc730-6267-405e-910a-5eced15bcf21/

Sign On Service Url

Enter the Service Identifier Url. This value is present under <md:SingleSignOnService  (node with HTTP-Redirect binding) > Location.

Fetch these values from the certificate downloaded in step no.7, Configure settings in onelogin server

For example: https://login.microsoftonline.com/f7ecc730-6267-405e-910a-5eced15bcf21/saml2

Logout Service Url

Enter the URL for logout. Generally same as Sign on URL

For example: https://login.microsoftonline.com/f7ecc730-6267-405e-910a-5eced15bcf21/saml2

Roles

Choose an option for the Roles from the drop-down menu. To know more see Configure Permissions for Role-Based Admin.

Device Group Set

Choose an option for Device Group Set from the drop-down menu. To know more, see Configure Permissions for Device Group Set Based Admin.

Jobs/Profiles Folder Set

Choose an option for Device Group Set from the drop-down menu. To know more, see Configure Permissions for Job Folder Set Based Admin.


3.  Copy the text value present inside EntityDescriptor > KeyDescriptor > ds:KeyInfo > ds:X509Data > ds:X509 Certificate and save it in a file with extension .cer. 

4.  Click Upload Certificate to Upload cer file. 

Keep the password field empty. If Upload Certificate option is not visible and Download Certificate is visible instead, then delete the existing certificate and again upload the saved cer file.

5.  Login to Azure portal and use the below url to login to 42Gears UEM server.

 https://<SureMDM Server URL>/console/ssologin/<SureMDM Account ID>

Note: Admin should enter their Server URL and Account ID into the above-mentioned URL.