Integrate Entra ID with SAML
Overview
These instructions describe the steps necessary to integrate the Application Portal with your Identity Provider (IdP) compatible with Entra ID SAML-based single sign-on.
Prerequisites
ENTRA ID
This document assumes that your Entra ID instance is already generally available, able to service logins for users, and that it simply needs additional configuration to integrate with the Application Portal. Creating an Entra ID instance and configuring it to synchronize with or federate to your on-premise identity management systems (e.g. traditional Active Directory) is not within the scope of this document. See Microsoft's site for general information on Entra ID and Configure single sign-on to non-gallery applications in Entra ID.
ENTRA ID ADMINISTRATOR ACCESS
The integration procedure requires involvement from an existing, authorized user within your Entra ID instance that has the necessary administrative permissions to add and configure Enterprise application within the directory.
CONGA ADMINISTRATOR SECURITY GROUP
As a part of setting up the Application Portal to integrate with you Entra ID instance, the Application Portal requires at least one AD security group to represent those users who shall be granted administrative rights to the Application Portal. The selected security group(s) may already exist and need not be specific to Conga, if you have an existing group that represents its security/domain administrators; however, some organizations may wish to create a separate security group specific to the Conga integration. This document does not cover how to create a new group or how to add a user to such a group. These actions are performed either directly in Entra ID or in your on-premise Active Directory (or other user management system). To ensure that the user performing the initial configuration has and retains access to administrative functions within the Application Portal, the user must select an administrative group from his/her own group memberships. This means that the initial configuration user must already be an existing member of at least one of the desired administrator security groups.
APPLICATION PORTAL METADATA
The metadata file for the Application Portal is available for each realm below
| CONGA CLOUD REALM | Application Portal SAML Metadata URL |
| US REALM 1 | https://login.us1s1.congacloud.com/x/saml2/metadata |
| US Preview | https://login.us0s1.congacloud.com/x/saml2/metadata |
| EU1 | https://login.eu1s1.congacloud.com/x/saml2/metadata |
| EU Preview | https://login.eu0s1.congacloud.com/x/saml2/metadata |
| AU REALM 1 | https://login.au1s1.congacloud.com/x/saml2/metadata |
| E1 EU1 | https://login.eu1s2.congacloud.com/x/saml2/metadata |
| US REALM 2 | https://login.us1s2.congacloud.com/x/saml2/metadata |
Entra ID Configuration
This section describes how to configure your Entra ID to add the Application Portal as an application.
CREATE AN APPLICATION IN ENTRA ID
- Open the Entra ID Portal: https://portal.azure.com
- Navigate to Microsoft Entra ID.
- Select Enterprise Applications.
- Click New Application.
- Click Create your own application.
- Populate the application name, for example: the Application Portal (you may add test, sandbox, or dev suffixes if applicable). Select Integrate any other application you don't find in the gallery (Non-gallery). Then click Create.
- Click Get started on Set up single sign on.
- Select SAML in the Select a single sign-on method.
- Edit the Basic SAML Configuration.
- Identifier (Entity ID): the Application Portal URL
CONGA CLOUD REALM APPLICATION PORTAL URL US REALM 1 https://login.us1s1.congacloud.com US Preview https://login.us0s1.congacloud.com EU1 https://login.eu1s1.congacloud.com EU Preview https://login.eu0s1.congacloud.com AU REALM 1 https://login.au1s1.congacloud.com E1 EU1 https://login.eu1s2.congacloud.com US REALM 2 https://login.us1s2.congacloud.com - Reply URL (Assertion Consumer Service URL):
CONGA CLOUD REALM the Application Portal SAML Assertion URL US REALM 1 https://login.us1s1.congacloud.com/x/saml2/assertion US Preview https://login.us0s1.congacloud.com/x/saml2/assertion EU1 https://login.eu1s1.congacloud.com/x/saml2/assertion EU Preview https://login.eu0s1.congacloud.com/x/saml2/assertion AU REALM 1 https://login.au1s1.congacloud.com/x/saml2/assertion E1 EU1 https://login.eu1s2.congacloud.com/x/saml2/assertion US REALM 2 https://login.us1s2.congacloud.com/x/saml2/assertion - Logout URL:
CONGA CLOUD REALM Application Portal SAML Logout URL US REALM 1 https://login.us1s1.congacloud.com/x/saml2/logout US Preview https://login.us0s1.congacloud.com/x/saml2/logout EU1 https://login.eu1s1.congacloud.com/x/saml2/logout EU Preview https://login.eu0s1.congacloud.com/x/saml2/logout AU REALM 1 https://login.au1s1.congacloud.com/x/saml2/logout E1 EU1 https://login.eu1s2.congacloud.com/x/saml2/logout US REALM 2 https://login.us1s2.congacloud.com/x/saml2/logout - Edit the Attributes & Claims section and set the Name ID Format to Persistent (preferred) or Email Address in the Required claim.
- Set Additional claims to the following attributes. Make sure to delete the namespace in the
Manage claim dialog:
CLAIM NAME VALUE DESCRIPTION Unique User Identifier (Name ID) Any uniquely identifying attribute (required): Can be any uniquely identifying attribute from the following selections. user.objectidis used as an example below.FirstName user.givenname(recommended): the Application Portal will attempt to find a first name from the response attribute named as FirstNameby default. Edit the claim that has valueuser.givennameand set the claim name toFirstNameif the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field.LastName user.surname(recommended): the Application Portal will attempt to find a last name from the response attribute named as LastNameby default. Edit the claim that has valueuser.surnameand set the claim name toLastNameif the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field.email user.mail(recommended): emailsets the user email associated with the user account. the Application Portal will attempt to find email from the response attribute named asemailby default. Edit the claim that has valueuser.mailand set the claim name toEmailif the claim exists. If the claim does not exist, add a new claim as described and then delete the value of the namespace field. This claim will be used by certain Conga applications for email alerts and notifications.username user.userprincipalname(required): the Application Portal will attempt to find a login username from the response attribute named as usernameby default. Add a new claim with these attributes: name:username, empty namespace, source attribute:user.userprincipalname.Group (required): the Application Portal will attempt to find roles assigned to the user from the response attribute named as Groupby default. Add a new claim with these attributes: name:Group, empty namespace, source attribute:user.assignedroles.DisplayName user.displayname(optional): the Application Portal will attempt to find a display name from the response attribute named as DisplayNameby default. If there is no display name, the Application Portal will concatenate the first name and the last name and use this as the display name. Add a new claim with these attributes: name:DisplayName, empty namespace, source attribute:user.displayname.Locale user.preferredlanguage(optional): the Application Portal will attempt to find a display name from the response attribute named as Localeby default. Add a new claim with these attributes: name:Locale, empty namespace, source attribute:user.preferredlanguage. This will be utilized by certain Conga applications for datetime, numerical and currency formatting. - Navigate back to Entra ID App registrations and select the Application Portal application.
- Click Create app role in App roles. Create an app role with Display Name and Value that makes sense for your organization. As an example, Conga-Admins can be used as the Display Name and Value and will be referenced in the documentation below.
- Navigate back to Entra ID and select Enterprise applications.
- Select the Application Portal application and select Users and groups.
- Click Add user/group and select individual users or groups and select the Conga-
Admins role to assign users and/or groups to the Conga-Admins role of the Application Portal application. Users with the Conga-Admins role have administrative access in the Application Portal application. Make sure to add the user who configured the identity provider (single sign-on connection) in Conga.
- Navigate back to the Single sign-on and download the Metadata File.
This metadata XML file will be needed to configure the identity provider (single sign-on connection on Conga).
Configure Single Sign-on Connection in Conga
The next step is to setup the Application Portal with the details from your Identity Provider. You may have already received an e-mail invite that provides you access to the Conga Platform, in which case you can refer back to the guide in order to complete the integration steps in the Application Portal.
If you've received a setup link from your Conga implementation specialist, proceed to the steps documented in the following guide: Integrate the First Identity Provider.
If you're lacking an e-mail invite or setup link, contact Conga Support for assistance.
Test Integration
Please follow the steps documented in the following guide: Test IdP Integration
Troubleshooting and other links
- Authentication fails with the error "The signed in user is not assigned to a role for the application."
The signed in user is not a member of the Conga-Admin-Group (either created in step 4 of Create Conga Admin Group or external directory such as Active Directory).
- The Admin tab is not available. - An attribute must exist in the authenticated SAML response with name
http://schemas.microsoft.com/ws/2008/06/identity/claims/rolecontaining the value of the role created in step 9 of Create Conga Admin Group section above. This value, Administrator in the above example, must match exactly to enable the Admin menu. - If you get an error in the form of
"errorID":"AUTH-001004","errorMessage":"Failed to verify SAML assertion."when attempting to log in, follow the steps below.
Open a SAML tracer of your choice (i.e SAML Tracer Chrome Extension) to debug SAML if you run into any errors. Find the SAML response sent to the Application Portal Assertion URL in the table above. This should contain an attribute statement like the one below; verify that the Group attribute is populated as expected and is not empty.
- Methods for assigning users and groups to an application.
- Entra ID Application Roles - Application roles
