<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=6813716&amp;fmt=gif">
Skip to content
English
  • There are no suggestions because the search field is empty.

Azure AD SAML setup

How to set up Azure AD SAML for darkhorse.app

⚠️ NOTE: this is an early access feature. The information in this article is likely to change. You may be required to update your configuration as we release new functionality or update our infrastructure.

Before you begin

The darkhorse.app SSO feature associates an email domain entirely with your organization's identity provider. This means any previously given darkhorse.app user credentials will not work, and users must sign in via Azure AD. Please ensure that any darkhorse.app users are granted access in Azure AD.

 

Known limitations

IdP-initiated sign-in is not supported by our authentication provider (AWS Cognito). This means that you will not be able to sign in by clicking a link in Azure AD - you must navigate directly to https://darkhorse.app and be redirected to Azure AD to sign in.

Migrating your organization to SSO is currently a manual process. Once we have your information, please allow a few days for us to make the necessary changes to ensure you don't lose access.

 

Setup instructions

1. Go to https://portal.azure.com

 

2. Search for "Enterprise applications"262453213-e6cd32f9-ed47-429f-a250-97db4403ccbe

 

3. Choose "New Application"262453481-599e7496-e6e1-47e2-8c85-358b3a3e9246-1

 

4. Choose "Create your own application"262454666-94aa1364-32a6-41d5-8f6d-5607828758ee

 

5. Name your app and choose "Non-gallery"262455309-7815fd53-38f0-4eb5-97e5-44afe17c10e1

6. Choose "Set up Single sign-on"262455889-98a5323c-2e18-4f39-93fb-a01a1e65b7df

 

7. Choose "SAML"262456072-c357d21f-620e-43a2-8a77-fe7e1ebb61da

 

8. Edit the "Basic SAML configuration"262456430-79b444d8-65dd-4ba1-b25d-cb73d03b6977

 

9. Fill in the following values and then hit "Save":
Identifier: urn:amazon:cognito:sp:us-west-2_lEfTGJ33J
Reply URL: https://des-apps-prod.auth.us-west-2.amazoncognito.com/saml2/idpresponse
Sign on URL: https://des-apps-prod.auth.us-west-2.amazoncognito.com/saml2/idpresponse

NOTE: Azure AD says the sign-on URL is optional, but it's mandatory for darkhorse.app


262457288-c3d8a9bc-3b0f-4ee9-9813-35c176e51463

 

10. Choose "Edit attributes and claims"

262458179-866b18ab-0bcc-48b2-879c-c409cc7af0cc

11. Ensure that https://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress is being sent. The others are optional.

262458295-5f0cf3a2-3ae9-4395-9e25-80ac9a403334

 

12. Copy the metadata URL and send this value to support@darkhorseemergency.com262458784-09b4a75f-2041-4188-a265-e0c3ed0f2815-1

13. Add appropriate users to the Azure application. Users who are not added to the Azure application will not be able to access Darkhorse apps.