Follow

Configuring Azure AD SAML2.0

Overview

FilesAnywhere supports SAML 2.0 SSO integration for various identity providers. For SSO integration with FilesAnywhere and SAML 2.0, the AzureAD Administrator needs to configure the FilesAnywhere application as a Trusted application as per the following steps.  

Also you will need to request FilesAnywhere to enable the single sign-on functionality.

 

Things to note:

  • Replace <<CLIENTID>> with your Client ID, I.E. 1324
  • Replace <<WEBURL>> with your Site URL, I.E. https://private.filesanywhere.com
  • Replace any instance below of 2331 with your Client ID, I.E. 1324

 

 

AzureAD Setup

  1. Login to your Azure Portal administration account.
  2. In the Azure Portal, navigate to Active Active Directory.


     
  3. Click on Microsoft Entra ID:

     
  4. Create New application:

      
  5. Click Add and then click on Enterprise application:
  6. Click Create your own application:
  7. Choose Intergrate any other application you don’t find in the gallery and click Create

     
  8. Choose Set up single sign on:


     
  9. Choose SAML


     
  10. Choose Basic SAML Configuration and click on Edit


     
  11. Keep Entity ID as below and ACS URL as per your user site URL with ClientID, click Save

    Field Name Field Value
    Reply URL / Assertion Consumer Service (ACS) <<WEBURL>>saml20.aspx?c=<<CLIENTID>>
    Identifier / Entity ID Filesanywhere.com
    ClientID <<CLIENTID>>

    Note: Your ClientID can be found on your login page at the bottom directly under the login box.



     

     

  12.  Step-1 will get updated as below:


     
  13. Edit Attributes and Claims section:


     
  14. Add clientID claim, Click Add new Claim -> Input value as below and Save:


     
  15. Edit all attributes (EmailAddress/FirstName/LastName/UserPrincipalname) as per below steps:
    1. Update name
    2. Remove Namespace value

      user.email

      user.firstname

      user.lastname

      userprincipalname

       

  16. Finally all attribute claims will look as below and ClientID should be replaced with your account ClientID:


     
  17. Collect and pass on to FilesAnywhere team to update and enable SSO for your account:
    Certificate (Base64)
    Login URL

     
  18. Assign Users(s) to newly added application:

  19. (Optional) Assign Group(s) to newly added application from the same area.
    See instructions for this below
     
  20. In this step you will need to request FilesAnywhere to turn on Single Sign-on for your account and click here to submit it: 
    1. Information collected in above steps:
      1. Initiate Single Sign On (SSO) URL
      2. Download Certificate
    2. If you can provide us with a few test accounts we could test the setup for you.

 

 

(Optional) Assign Group(s) Provisioning


1. Create the Group in your Admin Console

  1. Log into your admin console
  2. Click on Groups
  3. Click Add Group
  4. Create your group name and select your division as necessary
  5. Click on Sharing and set up your GroupShares for this group
  6. Click Save

2. Enable User SSO Group Mapping under your SSO settings within Site Configuration

  1. Log into your admin console
  2. Click on Site Configuration
  3. Click on Single Sign-On (SSO) Settings
  4. Navigate to User Self-Enrollment
  5. Click on "Allow user self-enrollment"
    This allows new SSO users to sign in and their accounts are automatically created
  6. Navigate to User SSO Group Mapping
  7. Click on Allow SSO Group Mapping
     
  8. Click Save Site Configuration

3. Create the group in Entra

  1. Log into Microsoft Entra
  2. Click on Users and groups
  3. Click on Add user/group
  4. From here you'll need to create the group with the exact same name that you used for the FilesAnywhere group

 

 

Login page

Once the Integration is enabled by FilesAnywhere, you will see the SSO button on your login page. Using Use Company Credentials button users can enter their Microsoft Azure AD credential to login into FilesAnywhere.

 

Still Have Questions?

If you need help or have additional questions, please contact us.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

0 Comments

Article is closed for comments.
Powered by Zendesk