Conga Product Documentation

Welcome to the new doc site. Some of your old bookmarks will no longer work. Please use the search bar to find your desired topic.

Integrate Entra ID with SAML

Overview

These instructions describe the steps necessary to integrate the Application Portal with your Identity Provider (IdP) compatible with Entra ID SAML-based single sign-on.

Prerequisites

ENTRA ID

This document assumes that your Entra ID instance is already generally available, able to service logins for users, and that it simply needs additional configuration to integrate with the Application Portal. Creating an Entra ID instance and configuring it to synchronize with or federate to your on-premise identity management systems (e.g. traditional Active Directory) is not within the scope of this document. See Microsoft's site for general information on Entra ID and Configure single sign-on to non-gallery applications in Entra ID.

ENTRA ID ADMINISTRATOR ACCESS

The integration procedure requires involvement from an existing, authorized user within your Entra ID instance that has the necessary administrative permissions to add and configure Enterprise application within the directory.

CONGA ADMINISTRATOR SECURITY GROUP

As a part of setting up the Application Portal to integrate with you Entra ID instance, the Application Portal requires at least one AD security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration. This document does not cover how to create a new group or how to add a user to such a group. These actions are performed either directly in Entra ID or in your on-premise Active Directory (or other user management system). To ensure that the user performing the initial configuration has and retains access to administrative functions within the Application Portal, the user must select an administrative group from his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.

APPLICATION PORTAL METADATA

The metadata file for the Application Portal is available for each realm below

CONGA CLOUD REALMApplication Portal SAML Metadata URL
US REALM 1https://login.us1s1.congacloud.com/x/saml2/metadata
US Previewhttps://login.us0s1.congacloud.com/x/saml2/metadata
EU1https://login.eu1s1.congacloud.com/x/saml2/metadata
EU Previewhttps://login.eu0s1.congacloud.com/x/saml2/metadata
AU REALM 1https://login.au1s1.congacloud.com/x/saml2/metadata
E1 EU1https://login.eu1s2.congacloud.com/x/saml2/metadata
US REALM 2https://login.us1s2.congacloud.com/x/saml2/metadata

Entra ID Configuration

This section describes how to configure your Entra ID to add the Application Portal as an application.

CREATE AN APPLICATION IN ENTRA ID

  1. Open the Entra ID Portal: https://portal.azure.com
  2. Navigate to Microsoft Entra ID.
  3. Select Enterprise Applications.
  4. Click New Application.
  5. Click Create your own application.
  6. Populate the application name, for example: the Application Portal (you may add test, sandbox, or dev suffixes if applicable). Select Integrate any other application you don't find in the gallery (Non-gallery). Then click Create.
  7. Click Get started on Set up single sign on.
  8. Select SAML in the Select a single sign-on method.
  9. Edit the Basic SAML Configuration.
  10. Identifier (Entity ID): the Application Portal URL
    CONGA CLOUD REALMAPPLICATION PORTAL URL
    US REALM 1https://login.us1s1.congacloud.com
    US Previewhttps://login.us0s1.congacloud.com
    EU1https://login.eu1s1.congacloud.com
    EU Previewhttps://login.eu0s1.congacloud.com
    AU REALM 1https://login.au1s1.congacloud.com
    E1 EU1https://login.eu1s2.congacloud.com
    US REALM 2https://login.us1s2.congacloud.com
  11. Reply URL (Assertion Consumer Service URL):
    CONGA CLOUD REALMthe Application Portal SAML Assertion URL
    US REALM 1https://login.us1s1.congacloud.com/x/saml2/assertion
    US Previewhttps://login.us0s1.congacloud.com/x/saml2/assertion
    EU1https://login.eu1s1.congacloud.com/x/saml2/assertion
    EU Previewhttps://login.eu0s1.congacloud.com/x/saml2/assertion
    AU REALM 1https://login.au1s1.congacloud.com/x/saml2/assertion
    E1 EU1https://login.eu1s2.congacloud.com/x/saml2/assertion
    US REALM 2https://login.us1s2.congacloud.com/x/saml2/assertion
  12. Logout URL:
    CONGA CLOUD REALMApplication Portal SAML Logout URL
    US REALM 1https://login.us1s1.congacloud.com/x/saml2/logout
    US Previewhttps://login.us0s1.congacloud.com/x/saml2/logout
    EU1https://login.eu1s1.congacloud.com/x/saml2/logout
    EU Previewhttps://login.eu0s1.congacloud.com/x/saml2/logout
    AU REALM 1https://login.au1s1.congacloud.com/x/saml2/logout
    E1 EU1https://login.eu1s2.congacloud.com/x/saml2/logout
    US REALM 2https://login.us1s2.congacloud.com/x/saml2/logout
  13. Edit the Attributes & Claims section and set the Name ID Format to Persistent (preferred) or Email Address in the Required claim.
  14. Set Additional claims to the following attributes. Make sure to delete the namespace in the

    Manage claim dialog:

    CLAIM NAMEVALUEDESCRIPTION
    Unique User Identifier (Name ID)Any uniquely identifying attribute(required): Can be any uniquely identifying attribute from the following selections. user.objectid is used as an example below.
    FirstNameuser.givenname(recommended): the Application Portal will attempt to find a first name from the response attribute named as FirstName by default. Edit the claim that has value user.givenname and set the claim name to FirstName if the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field.
    LastNameuser.surname(recommended): the Application Portal will attempt to find a last name from the response attribute named as LastName by default. Edit the claim that has value user.surname and set the claim name to LastName if the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field.
    emailuser.mail(recommended): email sets the user email associated with the user account. the Application Portal will attempt to find email from the response attribute named as email by default. Edit the claim that has value user.mail and set the claim name to Email if the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field. This claim will be used by certain Conga applications for email alerts and notifications.
    usernameuser.userprincipalname(required): the Application Portal will attempt to find a login username from the response attribute named as username by default. Add a new claim with these attributes: name: username, empty namespace, source attribute: user.userprincipalname.
    Group(required): the Application Portal will attempt to find roles assigned to the user from the response attribute named as Group by default. Add a new claim with these attributes: name: Group, empty namespace, source attribute: user.assignedroles.
    DisplayNameuser.displayname(optional): the Application Portal will attempt to find a display name from the response attribute named as DisplayName by default. If there is no display name, the Application Portal will concatenate the first name and the last name and use this as the display name. Add a new claim with these attributes: name: DisplayName, empty namespace, source attribute: user.displayname.
    Localeuser.preferredlanguage(optional): the Application Portal will attempt to find a display name from the response attribute named as Locale by default. Add a new claim with these attributes: name: Locale, empty namespace, source attribute: user.preferredlanguage. This will be utilized by certain Conga applications for datetime, numerical and currency formatting.
  15. Navigate back to Entra ID App registrations and select the Application Portal application.
  16. Click Create app role in App roles. Create an app role with Display Name and Value that makes sense for your organization. As an example, Conga-Admins can be used as the Display Name and Value and will be referenced in the documentation below.
  17. Navigate back to Entra ID and select Enterprise applications.
  18. Select the Application Portal application and select Users and groups.
  19. Click Add user/group and select individual users or groups and select the Conga-

    Admins role to assign users and/or groups to the Conga-Admins role of the Application Portal application. Users with the Conga-Admins role have administrative access in the Application Portal application. Make sure to add the user who configured the identity provider (single sign-on connection) in Conga.

  20. Navigate back to the Single sign-on and download the Metadata File.

This metadata XML file will be needed to configure the identity provider (single sign-on connection on Conga).

Configure Single Sign-on Connection in Conga

The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.

If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.

If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.

Test Integration

Please follow the steps documented in the following guide: Test IdP Integration

  • Authentication fails with the error "The signed in user is not assigned to a role for the application."

The signed in user is not a member of the Conga-Admin-Group (either created in step 4 of Create Conga Admin Group or external directory such as Active Directory).

  • The Admin tab is not available. - An attribute must exist in the authenticated SAML response with name http://schemas.microsoft.com/ws/2008/06/identity/claims/role containing the value of the role created in step 9 of Create Conga Admin Group section above. This value, Administrator in the above example, must match exactly to enable the Admin menu.
  • If you get an error in the form of "errorID":"AUTH-001004","errorMessage":"Failed to verify SAML assertion." when attempting to log in, follow the steps below.

Open a SAML tracer of your choice (i.e SAML Tracer Chrome Extension) to debug SAML if you run into any errors. Find the SAML response sent to the Application Portal Assertion URL in the table above. This should contain an attribute statement like the one below; verify that the Group attribute is populated as expected and is not empty.