You can integrate your Active Directory Federation Services (AD FS) instance to manage single sign-on for your members. To do this, perform the setup both in AD FS and Creatio.
In general, the following steps are required to set up Single Sign -On in Creatio:
- Download the file that contains the integration metadata. Read more >>>
- Perform the setup in AD FS. Read more >>>
- Perform the setup in Creatio. Read more >>>
Download the metadata
- Click the
button to open the System Designer.
- Click Single Sign On configuration.
- Click
. This opens a drop-down menu.
- Select “AD FS.” This opens the setup page.
- Click Get metadata.
- Save the file to your local machine.
Perform the setup in AD FS
-
Add a new Relying Party Trust to ADFS (Fig. 1).
Fig. 1 Relying Party Trust menu -
Select “Import data about the relying party from file,” as shown on the Fig. 2.
Fig. 2 “Import data about the relying party from file” option -
Specify the full website address in the identifier settings and click Add, as shown on the Fig. 3.
Fig. 3 Identifier -
Set up the rest of the parameters according to your security requirements. You can leave default values for test purposes.
-
Click Finish. This opens a window.
-
Click Add Rule and add a new SAML Assertion to SAML Response rule (Fig. 4)
Fig. 4 “Add rule” button -
Keep the default settings and click Next on the first step of the Rule Wizard. Set up a set of parameters to receive from the user’s data (Fig. 5). In this example, the user’s name and a list of domain groups will be passed via SAML Assertion.
Fig. 5 Rule parameters -
Click Save.
-
Open the Trusted Relay settings, go to the Advanced tab, and specify SHA-1 encryption according to the website certificate algorithm.
-
Add the public certificate key on the Encryption tab to set up the SAML encryption (Fig. 6).
Fig. 6 Encryption tab -
Add the logout endpoint and set the following parameters (Fig. 7) on the Endpoints tab:
-
Set Endpoint type to “SAML Logout”.
-
Set Binding to “Redirect”.
-
Enter https://site01.creatio.com/Demo_161215/ServiceModel/AuthService.svc/SsoLogout in the Trusted URL parameter.
Fig. 7 Endpoint parameters
-
-
Add the Logout Request certificate to the Signature tab, as specified on the Fig. 8.
Fig. 8 Logout Request certificate
Perform the setup in Creatio
Follow these steps to set up single sign-on in Creatio:
- Click the
button to open the System Designer.
- Click Single Sign On configuration.
- Click
. This opens a drop-down menu.
- Select “AD FS.” This opens the setup page.
- Fill out the AD FS tenant URL parameter. Creatio will populate other parameters automatically.
-
Fill out the provider's name to display on the Creatio login page in the Display name field.
Fig. 9 AD FS settings - Save the changes.
-
Turn on Just-In-Time Provisioning (optional). This mechanism automatically creates the corresponding Creatio user account with data from the identity provider, such as user group, employee name, contact information, etc. To do this, select the Create and update users data when log in (Just-In-Time Provisioning) checkbox and map the fields (Fig. 10).
Fig. 10 Set up Just-In-Time Provisioning -
Define your provider.
For Creatio version 8.0.7 and later
For Creatio version 8.0.3 – 8.0.6
-
Test whether the provider is working correctly (optional).
For Creatio version 8.0.7 and later
For Creatio version 8.0.3 – 8.0.6