Resources

VNTANA Resource AzureAD SSO

AzureAD SSO

VNTANA supports Single Sign-On (SSO) via Microsoft Azure, allowing enterprise customers to streamline access management.

Simply connect your Azure account to VNTANA, map Azure Groups to VNTANA Roles, and manage users directly in Azure. Your Organization Owner (typically your IT admin) only needs to handle role mapping within VNTANA.

How Does It Work

Preparing for SSO SAML and SCIM connection

To get started with Azure SSO integration:

  1. Identify your Azure admin – This is typically your IT Administrator, who will manage Azure Groups.

  2. Provide their email to VNTANA – We’ll send them an invitation to join your VNTANA account.

  3. Have them accept the invitation and create their user account – This person will become the Organization Owner and will manage user access and role mappings within VNTANA.

  4. Confirm account setup with VNTANA – Once their account is active, we’ll schedule a call to complete the SAML and SCIM connection.

Connecting Client’s Azure Account with VNTANA - SAML and SCIM Setup

Follow the steps below to connect your VNTANA Organization to an Azure AD account.
For detailed guidance on Azure AD configuration, please refer to AzureAD Guide for VNTANA SAML and SCIM Setup below.

  1. Log in – As the Organization Owner (Azure admin) log into VNTANA using your credentials (email and password).

  2. Navigate to SSO Settings – Open the User Profile menu, select Settings, and navigate to the SSO tab.

  3. Complete the SAML setup:

    • VNTANA will display the required information to input into Azure. Use the Copy buttons to quickly copy each field.

    • Paste the corresponding values from Azure into the VNTANA fields.

  4. Once all SAML fields are filled out, click Next to validate.

    • If successful, the SCIM section will appear.

    • If there’s an error, verify the information and try again.

  5. Complete the SCIM setup:

    • Copy the values provided in VNTANA and paste them into the SCIM settings in Azure.

    • Use the Copy buttons for convenience.

    • The Secret Token will encrypt after 30 seconds; regenerate it if needed using the Regenerate button.

  6. When both SAML and SCIM sections are complete, click Save to finalize the connection.

  7. It’s highly recommended to test the connection in Azure before proceeding.
  8. To make changes later, use the Edit button in the page header.

Once complete, proceed to Azure Group Role Mapping.

Mapping Azure Groups to VNTANA Roles

  1. Open the Users tab – Log in as the Organization Owner (Azure admin), go to the Organization Settings, and select the Users tab.

  2. Add a new role mapping – In the Azure Groups section, click the Add Role Mapping button.

  3. Enter Azure Group details

    1. Paste the Azure Group Name into the Name field.

    2. Paste the Azure Group ID into the ID field.

  4. Select a VNTANA Access Level – Choose the appropriate level of access for the Azure Group.

  5. Configure Workspace access (if applicable)

    1. Select a Workspace Role (only one per Azure Group).

    2. Open the Workspace dropdown, choose a Workspace, and click Add.

  6. Save the role mapping – Once all fields are complete, click Save.

Edit or Delete Role Mappings
  1. Access the Options menu – Click the Options button next to the Azure Group to Edit or Delete a mapping.

  2. Edit available fields – You can update the Group Name, VNTANA Access Level, and Workspace assignment.

  3. To change the Azure Group ID – Delete the existing mapping and create a new one with the correct ID.

Enabling SAML SSO + SCIM for Existing Organizations

  1. Complete all previous setup steps.
  2. Link Existing Users to Azure AD

    1. When SSO is first enabled for existing organizations with users, those users are not initially linked to Azure AD groups (and their role mappings) in VNTANA. As a result, any changes to the role mappings will not affect them.

    2. Existing users will be linked to their organization’s Azure AD groups upon their first SSO login using the Enterprise SSO option.

    3. During that first login:

      • The user’s roles will be recalculated based on the Azure AD group information received in the SAML token and the role mapping configured in VNTANA.

    4. During the SSO setup meeting with the organization, it is recommended to have at least a couple of users log in using the Enterprise SSO option to verify that the configuration is functioning correctly and that role mappings are being applied as expected.

  3. Verifying Azure AD Group Association

    1. The SA can check at any time whether there are users who are still not linked to Azure AD groups. To do this, they should:

      • Navigate to the Users view in the VNTANA Settings section.

      • Users with Azure Group information displayed are considered linked to the organization’s Azure AD.

      • Users without Azure Group information are not yet linked. This could be because the user has not yet logged in using the new Enterprise SSO option.

  4. Troubleshooting – Possible issues for users during the first login with the Enterprise SSO option:

    1. User Cannot Log In: Microsoft Error Displayed in Microsoft Login Popup Modal

      1. This typically indicates a misconfiguration in Azure on the organization’s side. Please contact the organization’s Azure Administrator.

    2. User Cannot Log In: UNAUTHORIZED or any other Error Response from Platform. This may occur if the user’s roles have been revoked. Possible causes include:

      1. No Azure Groups were received as part of the SAML token.

      2. The user’s Azure Group is not mapped to a VNTANA Role.

Adding External Users to Azure Groups

External vendors can access Organizations with SSO enabled. Follow the below steps to grant them access to the VNTANA organization.

  1. Add the external vendor as a Guest to internal Azure Groups.

  2. Map the Azure Group with external vendors to a VNTANA role within VNTANA’s Azure Group role mapping settings.

Signing in with SSO

Once the above steps are completed, users can sign into VNTANA with the Single Sign On (SSO) button. Users will not need to be invited to the organization and they will not need to create VNTANA credentials.

  1. As the Organization Owner, share the Organization Domain with your team—users signing in with SSO will need to enter this domain to access the VNTANA Platform.

  2. Sign in with Single Sign On – Use the SSO button on the VNTANA Sign In page.

  3. Enter the domain name – 

    1. The domain is the organization slug.

    2. For example: a user would need to type in erin for the organization https://platform.vntana.com/erin/

  4. Click Next to proceed.

  5. Sign in with Microsoft – 

    1. If the domain is validated, the user will proceed to the Microsoft log in pop-up. Complete the steps requested by Microsoft. Once signed they will be redirected to the VNTANA organization.

    2. If the domain is not validated, the user will need to check the input and try again.

    1.  

Azure AD Guide for VNTANA SAML & SCIM Setup

Create Azure Application and Set Up SAML

  1. Log in to the Azure Portal and Navigate to Enterprise applications → Create your own application

    1. In the ‘Create your own application’ view provide a name for the application and select Integrate any other application you don’t find in the gallery.

  2. In the Azure application details view → Select Single sign-on → Select SAML

  3. In Azure, navigate to the ‘SAML-base Sign-on view

    1. In the first step, we need to configure the service provider settings: Identifier (Entity ID), Reply URL, and Sign-on URL. This information is available in the VNTANA Platform.

    2. In the VNTANA Platform, go to Settings → SSO Settings. Copy the required information from the VNTANA Platform into the corresponding fields in Azure, click the Save button, and return to the ‘Set up Single Sign-On with SAML’ view.
  4. In the ‘SAML Setup’ view, edit the Attributes & Claims section to ensure that user.groups is included in the claims sent in the token. The number of groups included in a token is limited to 150 for SAML assertions, so it’s recommended to include only Groups assigned to the application. More information about the restriction on the number of groups in the token here.

  5. The next step is to share all the necessary data from Azure with the VNTANA Platform:

    1. Download the Base64 certificate, open it in any text editor, and copy the certificate content. Then, paste it into the platform. Make sure to include the PEM headers and footers ( -----BEGIN CERTIFICATE----- and ----END CERTIFICATE----- ).

    2. Copy Azure’s Login URL and Microsoft Entra Identifier to the VNTANA Platform.

  6. The test section of the SAML Setup will not work until a user is assigned to the Azure Enterprise application.

SCIM Setup

  1. In the Azure’s application Overview

    1. Select Provisioning

    2. Click either New Configuration or Connect your application

  2. Go to the VNTANA Platform to retrieve the following information:

    1. Endpoint URL (Tenant URL)

    2. SCIM Secret token

  3. Save the configuration in the VNTANA Platform, then test and create the configuration in Azure.

  4. Configure the SCIM Attribute Mapping in Azure: in the left menu panel, click on Attribute Mapping (preview)

    • Click on Provision Microsoft Entra ID Groups

      • In the Target Object Actions section, uncheck Create and Delete

        • We do not create groups or delete groups on the VNTANA side, but we track membership changes within the groups.

      • Map the displayName attribute to the Microsoft Entra objectId

      • Save the changes

      • The Attribute Mappings should look like the following view 

      • Click on Provision Microsoft Entra ID Users

        • Ensure that all Target Object Actions are checked.

        • In the Attribute Mappings section, keep only the following attributes: userName, active, displayName.

        • The final Attribute Mappings should look like the following view

        • Save the changes

  5. Check the settings

    • In the left menu, click on Provisioning → Settings and check if Sync only assigned users and groups is selected.

    • This step aims to prevent the synchronization of all users and groups created within the organization’s Azure AD to the VNTANA Platform.

  6. Test with Provisioning on Demand

    1. Go to Provisioning on Demand

      1. Search for a user and click on Provision.

      2. Before testing, assign some groups and users to the application from the Users and groups menu option.

    2. Navigate to the Provisioning Overview

      1. Click on Start Provisioning

Azure Groups to VNTANA roles mapping

  1. In the VNTANA Platform, go to Settings → Users → Azure Groups, and click the Add Azure Group Role Mappings button.

  2. In Azure, navigate to Groups → All Groups, and search for the group that should be mapped to a VNTANA role. From the group’s details view, copy the Group Name and Object ID into the VNTANA Platform, then click the Save button.

    1. Role Mapping for Organization Access

      1. The users in the selected Azure Group will be assigned the Organization Admin Role in the VNTANA Platform.

    2. Role Mapping for Workspace Access

      1. Users in the selected Azure group will be assigned the selected workspace role in the chosen workspaces when they are created in the VNTANA Platform

External Users Management

  1. External users can be invited to the company’s Azure AD and added to an Azure group that is mapped to a VNTANA role.




Troubleshooting

On This Page

Accelerate Your
Digital Transformation

Learn how our platform can automate your 3D process.

Tap the magnifying glass to the left of your screen to search our resources.