Authentication / SSO
Single Sign On capability could be setup in Azure Active Directory so that AAD plays the role of an identity provider when logging in CPQ Designer.
Configuring the SSO requires to follow the steps below:
Azure Active Directory Configuration
ASSIGN PREMIUM LICENSE TO USER
In the Domain, open the License settings tab:
Then open the license Plan and assign the user to it (the Assign button is at the bottom of the page):
ADD AN UNLISTED APPLICATION
Here is an example of the information to fulfill:
Only HTTPS is supported. You need to have a CPQ Designer with https available to use the Single Sign-on capability.
In parallel, on the CPQ side, the issuer URL and the Single Sign-On Service URL have to be entered in the cameleon.properties file.
For more details on these parameters, please look for SAML parameters in the CPQ Administration guide.
ADD CPQ CUSTOM ATTRIBUTE
In the application, with Premium License only, an Attributes Step allows adding the CPQ Custom Settings mandatory to connect to CPQ Designer. For instance:
ASSIGN USER TO THE APPLICATION
To allow a user to access the Application, open the Users and Groups menu in the application and assign this user to the application:
CPQ Configuration
NEW PARAMETER IN CAMELEON.PROPERTIES
Because AAD SAML response doesn't support federation ID, the default name ID policy format is not correct. To use SAML with AAD, add the property nameIDPolicy in cameleon.properties on the CPQ server.
For more details on the value to give to this parameter in CPQ, please refer to the CPQ Administration Guide on Designer SSO.
