Integrating with the Application Portal Using the Setup Link
Overview
These instructions describe the steps necessary to configure the Application Portal and establish a trust with your single sign-on Identity Provider (SSO IdP) for the first time. Once complete, subsequent changes or adding secondary identity providers can be performed directly within the Application Portal user interface, by users with sufficient privileges, when logging in through the initial identity provider.
Prerequisites
This document assumes that the setup requirements for your chosen Identity Provider have been completed in preparation for establishing a trust with the Application Portal.
Since a trust relationship between your identity systems and Conga is not yet established, you will need a hyperlink (URL) containing a time-limited, one-time-use code to authorize the integration. This link will be provided by Conga and, for security reasons, expires 72 hours after creation. If your link has expired or cannot be located, please contact Conga Support for assistance to reissue the first-time setup credential.
Using the Identity Provider Setup Wizard
Conga provides a Web-based setup wizard, accessed from your first-time setup link, to ease the integration process. Conga recommends using a private (or "incognito") browser window during the setup process; this ensures prior authentication state and settings with your provider do not obscure any problems.
STEP 1: SELECT THE IDENTITY PROVIDER TYPE
Select the most appropriate Provider type from the drop-down list. If your specific provider is not listed, select a compatible protocol supported by your provider, such as SAML 2.0. While not listed as distinct choices, the SAML 2.0 option enables any SAML 2.0-compatible provider with support for Service Provider (SP) initiated sign-on, including but not limited to:
- Entra ID (via SAML)
- Ping Identity
- SecureAuth
- Okta
- SAP Cloud Platform
- OneLogin
STEP 2: PROVIDER CONFIGURATION DETAILS
The wizard will prompt you for the required and optional fields appropriate to the provider type selected in the prior step.
Entra ID using OpenID Connect
This provider type requires your Entra ID domain, plus an application ID and secret key specific to your Conga integration, generated by Entra. The key's effective start and end dates are for your reference in the event it becomes necessary to rotate the application secret in the future.
Other providers based on the SAML 2.0 Protocol
Salesforce platform identity and Microsoft AD FS both use the SAML 2.0 protocol. The exact fields prompted in the user interface may vary, slightly, based on the selected provider, but all share the same process with other generic SAML 2.0-based providers. Conga recommends uploading an XML-formatted SAML metadata file, obtained from your provider, when available. Metadata import is faster and minimizes data entry mistakes since the user interface will pre-fill many of the fields. All fields can be reviewed and corrected after import, if necessary.
Conga Metadata URLS
SAML Metadata for the Application Portal is available from the following URLs in an unauthenticated format:
STEP 3: SELECT THE SIGN-IN USERNAME FORMAT
The Application Portal requires knowledge of your users' standard username format, so that it can identify users attempting to access your company's accounts and direct them to the appropriate identity provider.
Conga recommends using an email-style username, where your user identifiers are suffixed by the '@' symbol followed by a fully-qualified domain name owned by your organization. It is not required that an e-mail-style username format resolve to a real, working e-mail inbox. When configuring multiple Conga environments or multiple Identity Providers to support production and pre-production use cases, Conga recommends using the following alternative formats,
where example.com is replaced by your organization's domain:
| ENVIRONMENT PURPOSE | SUGGESTED USERNAME FORMAT |
|---|---|
| Sandbox | @example.com/sandbox |
| Test | @example.com/test |
| Production | @example.com |
The above convention reserves the @example.com format for the production environment, which may
not be the first Conga environment provisioned for your solution.
When you are ready to proceed, click the Save & Finish button to save your changes.
STEP 4: SIGN IN AND ADMINISTRATOR GROUP ACCESS
Once the above steps are completed, click the Login to the Application Portal button to launch a new window or tab. The intended administrator (or super user) for managing identity and access control with Conga should sign in using the username format configured in step 3.
You must complete your first login by clicking the green login button below! If you attempt to open another browser window or session, your request will be rejected, as the setup is not complete. If the session was closed before the group assignment is performed, you will need to reopen the setup link to reach the Wizard complete step below and log in successfully.
Upon successfully signing in to the Application Portal for the first time, you will be prompted to select one of the groups sent by your identity provider. The list will only display groups for which the signed-in user is already a member. The selected group will be granted full administrative access to the portal. This selection is mandatory, and it is important that you complete this step. The assigned group can be modified, or more groups added, later.
In this example, any user who is part of the PROS-Admin group will have administrative access to the Application Portal. Once you have selected the correct group, click Save to save your changes.
You have completed integrating your identity provider with the Application Portal.
Troubleshooting
Q: I was not able to sign into the Application Portal after saving all of my changes.
A:
- The link to the Identity Provider Setup Wizard can be re-used for 72 hours to go back and change any configuration settings as needed.
- Double-check that your identity provider is configured properly by visiting the relevant provider integration guide in the documentation portal.
- Make sure that the user testing sign-in has the proper permissions within your identity provider to initiate single sign-on.
- Remember to use an incognito browser window when accessing the wizard and testing sign-in.
Q: I was able to sign into the Application Portal, but I don't see any groups in the drop-down to select for administrative access.
A:
- If you are integrating with Entra ID using the OpenID Connect protocol, double-check that permissions are set properly in Entra ID to allow the Application Portal to read groups within your directory.
- If you are integrating with a SAML-based identity provider, make sure you have configured your identity provider to send an attribute in the SAMLResponse to provide the Application Portal with the group information. The name of this attribute should match with the identity
provider Group attribute setting in the configuration step of the wizard.
- Verify that you are a member of the group from your Identity Provider requiring Admin access to the portal.
- Once you have made the necessary changes, go through the Identity Provider Setup Wizard again. You can skip all completed steps and test signing in again to verify groups are now available to select.
If you continue to experience issues, please contact Conga Support for assistance.
