> ## Documentation Index
> Fetch the complete documentation index at: https://docs.frankieone.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing Your Azure SAML Single Sign-On (SSO) Setup

## Prerequisites

Ensure you’ve obtained your metadata from FrankieOne for your environment.

## Procedure

1. Sign in to your Azure Portal and navigate to **Azure Active Directory**.

   <img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/7439336-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=f9ee45ab1777d60d363aea1e89fbefa9" alt="" width="1249" height="678" data-path="images/v1/introduction/getting-started/7439336-image.png" />

2. In the **Overview** section, select **New** , then choose **Add Enterprise Application**.

   <img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/9bc6205-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=11be4f1ebbb58721bc7f175ad78ed2e9" alt="" width="1289" height="290" data-path="images/v1/introduction/getting-started/9bc6205-image.png" />

3. Select **Create Own Application** , provide a suitable name, choose the **Integrate any other application you don’t find in the gallery** option, and then select **Create**.

   <img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/2821351-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=dbf87b54569fd9f5d9246871442dce81" alt="" width="1909" height="934" data-path="images/v1/introduction/getting-started/2821351-image.png" />

   For this exercise, we’ll assume you already have users in your Active Directory (AD) account and won’t cover the process of creating users and assigning access to this application.

4. On the **Get Started** page of the newly created application, select the **Set up Single Sign-On option** (option 2 in the image below).

   <img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/eb834aa-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=7f1b45c8b70cee73e025661a95d829ba" alt="" width="1876" height="330" data-path="images/v1/introduction/getting-started/eb834aa-image.png" />

   <img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/aa1d102-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=77f2a4cb080cc417ee47daaf84784909" alt="" width="1876" height="329" data-path="images/v1/introduction/getting-started/aa1d102-image.png" />

When prompted for the Single Sign-On method, choose **SAML**.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/7d24bf2-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=6f7fa6030292e5bbccc39aaf844a7271" alt="" width="1825" height="681" data-path="images/v1/introduction/getting-started/7d24bf2-image.png" />

5. Select **Upload Metadata** file to have Azure pre-fill some sections for you.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/43b0f0b-image.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=69eb681c69ae19a48e69ebdf99bccedb" alt="" width="1905" height="433" data-path="images/v1/introduction/getting-started/43b0f0b-image.png" />

The details below will auto-fill once the data has been passed into Azure. Select Save to proceed.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/0197a76-919597a-image2.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=c022b5ab6969d6802ffd4e09cd70e4b4" alt="" width="1901" height="890" data-path="images/v1/introduction/getting-started/0197a76-919597a-image2.png" />

6. Select Attributes & Claims and add the following attributes to be passed on to FrankieOne:

   * Email
   * fullName
   * roles (Available from [here](/docs/v1/portal/sso-setup))
   * After completing the above step, the attributes section of your SSO might look like the image below.

After completing the above step, the attributes section of your SSO might look like the image below.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/attributes.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=3f21cea2ee06452e45477bb8e1a741df" alt="" width="991" height="581" data-path="images/v1/introduction/getting-started/attributes.png" />

The Roles claim should be a comma-separated list of roles currently available in your portal. To manage users with different permissions, the value should be conditional and based on group assignment. See the image below showing how groups have been used to assign roles.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/attributes_1.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=895d0a93ea55415d5ac14b7906733b4a" alt="" width="1882" height="1236" data-path="images/v1/introduction/getting-started/attributes_1.png" />

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/attributes_2.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=2d87cc453eed51cf75cb369186f42991" alt="" width="1882" height="682" data-path="images/v1/introduction/getting-started/attributes_2.png" />

The group names aren’t passed to FrankieOne, only the comma-separated list of data you’ve entered in the “values” section.

After you’ve configured this, download the Federation Metadata XML and provide it to FrankieOne to complete the setup.

<img src="https://mintcdn.com/frankieone-f5583b1b/YJ8U5h0OEQLOVp6h/images/v1/introduction/getting-started/saml.png?fit=max&auto=format&n=YJ8U5h0OEQLOVp6h&q=85&s=9212b4fa200e1df5efb738574d916ad2" alt="" width="809" height="266" data-path="images/v1/introduction/getting-started/saml.png" />

Once you receive confirmation from FrankieOne about setting up your SSO, you can test the SSO login. You might want to add users into the application itself, depending on how Azure has been configured for Access to Applications.
