First-time Identity Provider Setup from E-mail Invite
Introduction
This guide contains instructions on how to obtain initial access to Conga resources and proceed with the initial steps of integration in order to get your users access to and using the Conga Platform!
Authentication to Conga Active Directory
- One or more of your users received an email invite from Microsoft to access their Conga resources.
This invite allows up to five users to access their Conga resources and perform the Identity Provider setup to enable access to appropriate groups within your organization.
- Accept the invitation, and you will need to authenticate with your Microsoft account, if you are not authenticated already.
- If you don't already have a Microsoft account associated with your work e-mail address, you will need to set up an associated account, select the appropriate verification method. Follow Microsoft's guide in order to set up a Microsoft account and select the verification two-step verification method of your choice (text, email or Microsoft Authenticator).
- Complete authentication of your Microsoft account. The exact steps of authenticating may differ depending on what multi-factor authentication your organization has set up.
- You'll need to accept the Permissions requested by the Conga-hosted Entra ID instance in order to complete authentication and gain access to your resources.
Initial Access to Conga resources
- Upon clicking accept, the authentication should be complete, and you should be able to select an environment and view its Conga applications and resources.
- You should have access to the applications associated with your entitlement and can explore the various options. The next step will be to set up integration with your company's identity provider (IdP). There are a number of options available for integration, and setup will be done by accessing the Admin Menu, then Global Settings, then Identity Providers. Select Add Identity Provider.
Identity Provider (IdP) integration
- You will need to select a name for your identity provider of your choice, and you will then need to select the type of integration you wish to perform.
- At this point, there are five selection options for integration, and the process for completing each integration will differ significantly.
- Active Directory Federation Services (ADFS): Only choose this option if you are integrating Active Directory Federation Services, typically in an on-prem deployment. You should not choose this option if you are integrating Entra ID. Guide for Active Directory Federation Services integration.
- Entra ID (OpenIDConnect): This is an option to integrate Entra ID using the OpenIDConnect (OIDC) protocol. The other option for integrating Entra ID is SAML 2.0, so you should come to a decision which of the two options (OIDC and SAML) your IT team would prefer supporting. Guide for Entra ID OpenIOConnect integration.
- OpenIDConnect: This is an option to integrate Identity Providers other than Salesforce or Active Directory using the OpenIDConnect protocol. You should check whether your Identity Provider provides or prefers the OpenIDConnect protocol. Guide for OpenIDConnect integration.
- SAML 2.0: This is an option to perform a generic integration using the SAML 2.0 protocol, as stated in the second option, this is also a valid selection for Entra ID, among other identity providers. Guide for SAML 2.0 integration.
- Salesforce (SAML 2.0): This is an option to perform a SAML integration with Salesforce and add Salesforce as an identity provider. Guide for Salesforce SAML 2.0 integration.
Next Steps
- Test your Identity Provider integration, then move on to assigning access to the appropriate groups in your organization.
