> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pads4.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How to configure Single Sign On Azure for PADS4

The below process helps you configure your PADS4 CMS installation touse Azure SSO.

<Warning>
  From PADS4 2025.2 onward, this feature is part of PADS4 CTRL Center. For more information, see CTRL Center > Administration > Identity.
</Warning>

## Azure settings

It is necessary to configure the Azure instance to allow users within yourorganization to access the PADS4 (Legacy) CMS application. To enable this, please follow the steps in this document :

## Step 1 : Navigate and login to your "Azure portal" page as an admin

[https://portal.azure.com/](https://portal.azure.com/)

## Step 2 :  Select the "Microsoft Entra ID" option

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/MicrosftentraID.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=9c10b2a614a3bf87aba2cad79038ad18" alt="Microsftentra ID Pn" width="806" height="112" data-path="images/MicrosftentraID.png" />

## Step 3 : On the left hand side panel, select "Enterprise Applications"

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/EnterpriseApplications.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=65badcbfcd4974b48cf37a29c7af8066" alt="Enterprise Applications Pn" width="345" height="672" data-path="images/EnterpriseApplications.png" />

# **Important**

<Warning>
  If you \*\*<u>don't</u> \*\* want to use an Application Proxy onyour on-premise application then continue on step 4 below and skip steps 7 and 8.

  If you \*\*<u>do</u> \*\*want to use an Application Proxy for your on-premise application then proceed to step 7 and skip steps 4, 5 and 6.
</Warning>

## Step 4 : Select the "+ New application" option at the top of the screen

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step4+newapplication.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=8fe6df20c6f4991f16183d46ac5ed6de" alt="Step4+newapplication Pn" width="806" height="244" data-path="images/step4+newapplication.png" />

## Step 5 : Click on "Create you own application"

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step5.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=bfce632f366f1df5240e2bebe99b5b1b" alt="Step5 Pn" width="806" height="582" data-path="images/step5.png" />

## Step 6 : Fill in the information requested in the form and click create

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step6.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=d8036d9b5dae323d956b94858e3c567b" alt="Step6 Pn" width="806" height="539" data-path="images/step6.png" />

<Warning>
  Skip this step (7) if you don't use an Application Proxy.
</Warning>

## Step 7 : Creating a connector group / application proxy connector:

Select the **Manage Application Proxy Connectors** **section**

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step7.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=d3ac4f06da782d712f76ccd11503a764" alt="Step7 Pn" width="806" height="402" data-path="images/step7.png" />

1. In the Application Proxy menu, Select the + Download ConnectorService
2. Agree to the terms and download the **<u>AADApplicationProxyConnectorInstaller.exe</u>** file to the server PC.
3. Run the installer and make sure to validate your Azure Administratorcredentials during the setup.

   <img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step8.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=582636ace09917ad96949e39c7e5fb98" alt="Step8 Pn" width="409" height="288" data-path="images/step8.png" />
4. After the installation is complete, select the **+New Connector** Groupsection
5. Create a default name for your connection. For example : **SSO Connector**
6. Select your server machine from the Connector list
7. Select the region where your machine resides.

   <img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step9.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=2b464072c2bda17cc886729ff30ada8c" alt="Step9 Pn" width="324" height="333" data-path="images/step9.png" />
8. Save your new connection here.
9. Head back to the Enterprise Applications section, and select the **"Add your own on-premises application"**

## Creating an on-premises application within Azure

1. Select **Add an on-premises application**

   <img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/step10.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=b58cdef2d2b566873c904781dbf99cc7" alt="Step10 Pn" width="806" height="647" data-path="images/step10.png" />

<Warning>
  Skip this step (8) if you don't use an Application Proxy.
</Warning>

## Step 8 : Fill in the information requested in the formand click create.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Addyouownonpromiseapp.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=318afb5546b83aa6387f485a74bd7b72" alt="Addyouownonpromiseapp Pn" width="806" height="869" data-path="images/Addyouownonpromiseapp.png" />

### Example :

Name : PADS4 CMS

Internal URL : URL of the PADS4 CMS installation ([https://servername](https://servername))

Pre-authentication : Azure Active Directory

Connector Group : SSO Connector (default). <u>This is the connector group you have just set up</u>

Then Click on the add button

## Step 9 : Navigate to the newly created application

1. Navigate to the newly created application by selecting **“ Enterprise Applications"** and use t**he search bar** to find your application. **Select it** and then navigate to "Users and Groups" :

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/userandgroups.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=f7a8eef4d1de1909d23dcb32fe747910" alt="Userandgroups Pn" width="806" height="732" data-path="images/userandgroups.png" />

2. Add the users and groups that will have access to the application byselecting the **“ Add user/group ”** option

<img src="https://mintcdn.com/pads4/NThVTmlmP0lAiQnP/images/robinsso.png?fit=max&auto=format&n=NThVTmlmP0lAiQnP&q=85&s=47a430bc7ee515e51130e38e54225bac" alt="Robinsso Pn" width="806" height="293" data-path="images/robinsso.png" />

3. Select **“None Selected”** option to gain access to the groups and users :

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/add.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=6c9801952a8bc21641fbc692169e40ac" alt="Add Pn" width="806" height="190" data-path="images/add.png" />

4. Use the search bar to search for a user or group. Click **"select"** and **"assign"**  upon completion

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/add2.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=25250d7adb834a032682c16508516ac9" alt="Add2 Pn" width="806" height="258" data-path="images/add2.png" />

<Warning>
  It is highly recommended to create a PADS4 CMS user group withthe Windows Server AD as the source.
</Warning>

## Step 10 : To configure Single Sign On (SSO)

Select **"Single sign-on option"**  in the left pane and then **"SAML"**

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/10.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=e3bb2fd7f4b5c152b0485f0b5b1345b5" alt="10 Pn" width="806" height="370" data-path="images/10.png" />

## Step 11 : Select "Edit" on the "Basic SAMLConfiguration"

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image23.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=7b491c58fa7895d27f2dd68a442fd52d" alt="Image23 Pn" width="806" height="392" data-path="images/Image23.png" />

Select “ Add identifier ”  and **" Add Reply URL ”** as provide the value per the below example:

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image24.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=69aeb7262e6a8568f635dd346da99cec" alt="Image24 Pn" width="806" height="484" data-path="images/Image24.png" />

## Example :

**Identifier**: Local PADS4 CMS URL with /Saml2 **(e.g:** [https://robin.pads365.com/crystal/domain/Saml2](https://robin.pads365.com/crystal/domain/Saml2))

If a unique network port is being utilized, be sure to include this in above string.

E.g : [https://robin.pads365.com:444/crystal/domain/Saml2](https://robin.pads365.com:444/crystal/domain/Saml2)

**Make sure** you specify your PADS4 domain at "domain" in theURL

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image25.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=ba0d89e0665c9524740aa84090552de8" alt="Image25 Pn" width="806" height="62" data-path="images/Image25.png" />

If you use the default domain name it will be : [https://robin.pads365.com/crystal/pads/Saml2](https://robin.pads365.com/crystal/pads/Saml2)

Reply URL : Local PADS4 CMS URL with /Saml2/Acs **(e.g:**[**https://robin.pads365.com/crystal/domain/Saml2/Acs**](https://robin.pads365.com/crystal/domain/Saml2/Acs) )

If a unique network port is being utilized, be sure to include this in above string.

E.g [https://robin.pads365.com:444/crystal/domain/Saml2/Acs](https://robin.pads365.com:444/crystal/domain/Saml2/Acs)

**Make sure** you specify your PADS4 domain at "domain" in theURL

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image26.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=41ddc0fc7e43a20f75984eb088b065dd" alt="Image26 Pn" width="806" height="62" data-path="images/Image26.png" />

If you use the default domain name it will be:

[https://robin.pads365.com/crystal/pads/Saml2/Acs](https://robin.pads365.com/crystal/pads/Saml2/Acs)

<Info>
  **Remark :**  If you have configured SSO on a version before 2023.1, the domain name wasn't required in the URL when using only one domain. From version 2023.1 onwards, the domain name is required in the URL both for one and multi-domain setups.

  Therefore, when updating from a version before 2023.1 with SSO configured, to the latest release, make sure to add the domain to both the Identifier and Reply URL.

  **Be sure to "Save" these configurations.**
</Info>

## Step 12 : Whilst in the “ Single sign-on ” menu, select “Edit ” on the “ Attributes & Claims ” section.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image27.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=8ba94eb56f36e8d7c3dad42fcbfa621c" alt="Image27 Pn" width="806" height="562" data-path="images/Image27.png" />

**By default, you would have a list of claims already, however, it isrequired that the claims matches the below example for successful authentication :**

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image28.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=1b2d4ba070db3c5b2b6b4676899738d7" alt="Image28 Pn" width="605" height="307" data-path="images/Image28.png" />

Add the primarysid claim : Select “Add new claim”

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image29.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=846f3951f81f44106bc1985c4888ff6a" alt="Image29 Pn" width="806" height="455" data-path="images/Image29.png" />

**As per the example provided above, add a new claim to match the example table :**

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image29.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=846f3951f81f44106bc1985c4888ff6a" alt="Image29 Pn" width="806" height="455" data-path="images/Image29.png" />

Name : **primarysid**

Namespace : [**http://schemas.xmlsoap.org/ws/2008/06/identity/claims**](http://schemas.xmlsoap.org/ws/2008/06/identity/claims)

Source attribute : **user.objectid**

**Save all configurations.**

## Add / Edit the "group" claim detail as per below example and save

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image30.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=e037ac63ecebbd2f15b1122649e8e155" alt="Image30 Pn" width="806" height="635" data-path="images/Image30.png" />

Name : **group**

Namespace : [http://schemas.xmlsoap.org/claims](http://schemas.xmlsoap.org/claims)

<Info>
  Remark : If you now experience the following behavior, the SSObutton on the login page works and you are able to input yourcredentials but it will get redirected to the PADS4 Login portal with "Noaccount is defined for your authentication request" in the URL.

  **There can be 2 causes**

  the group claim is incorrectly configured

  The user you are trying to log in with has the same email addressalready configured to a CMS / Workspace user.
</Info>

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image31.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=4406286834de68b9d4d059c225d1592f" alt="Image31 Pn" width="806" height="73" data-path="images/Image31.png" />

<Info>
  You **have now prepared SSO within Azure for your PADS4Application.**
</Info>

# Information Required for SSOConfiguration in PADS4 CMS

## In order to configure SSO within PADS4 CMS,you will require the following :

Certificate of the federation server

Federation Service Identifier

SAML SSO URL

Metadata URL

URL of the Relying party and;

Group ID of the User Group you have assigned to the application.

## 1. Obtaining the “Certificate of the federationserver”

Within your application, select **“ Single sign-on ”** in the left pane

Scroll down to the **“ SAML Certificates ”** heading

Select the **“ Download ”** option next to the “ Certificate (Raw) ” option.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image32.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=a406fd396706e3a577bb38b07ba7535f" alt="Image32 Pn" width="806" height="429" data-path="images/Image32.png" />

## 2. Obtaining the “ Federation Service Identifier ”

Within your application, select **“ Single sign-on ”** in the left pane

Scroll down to the **“Set up“ your\_application\_name ”** heading

Select the **“ Copy ”** option next to the **“ Azure AD Identifier ”** option.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image33.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=79707572394f6c20eb372bb65496c9bf" alt="Image33 Pn" width="806" height="583" data-path="images/Image33.png" />

## 3. Obtaining the “SAML SSO URL"

Within your application, select **“ Single sign-on ”** in the left pane

Scroll down to the **“ Set up “your\_application\_name ”** heading

Select the\*\*“ Copy ”\*\*   option next to the **“ Login URL ”**  option.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image34.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=f4532d98fac0c33ababf96297ecef3ce" alt="Image34 Pn" width="806" height="583" data-path="images/Image34.png" />

## 4. Obtaining the “Metadata URL"

Within your application, select “**Single sign-on ”**  in the left pane

Scroll down to the \*\*“ SAML Certificates ” \*\*heading

Select the **“ Copy ”** option next to the **“ App FederationMetadata URL ”** option.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image35.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=48f730f0ce6b465ed8d50ef05fdae7ad" alt="Image35 Pn" width="806" height="497" data-path="images/Image35.png" />

## 5. Obtaining the “URL of the Relying party”

Within your application, select **“ Single sign-on ”** in the left pane

Scroll to the **“ Basic SAML Configuration ”** heading

Copy the string next to the \*\*“ Identifier (Entity ID) ” \*\*option.

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image36.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=da910f91547564fa6159e3e2f60c60d8" alt="Image36 Pn" width="806" height="392" data-path="images/Image36.png" />

## 6. Obtaining the “Group ID” of the group you assigned to your application:

<Info>
  For **every user group added to utilize the PADS4 CMS application, a mapping table will be required to add the groups to the interface. Please provide the installers the Group ID’s and names of the Groups from Azure to ensure users will be able to login.**
</Info>

Select **“home”** in portal.azure.com and select **“Microsoft Entra ID”**

Navigating to **“Groups”** in the left pane

Search for the group you assigned within your application and copy the\*\*“Object Id”\*\*

<img src="https://mintcdn.com/pads4/RiMI-g4NjECUn-K4/images/Image37.png?fit=max&auto=format&n=RiMI-g4NjECUn-K4&q=85&s=352169ad39120410d05f20130717420e" alt="Image37 Pn" width="605" height="228" data-path="images/Image37.png" />

## 7. Now that all of the above information has been gathered, PADS4 CMS can now be configured to make use of SSO.
