Microsoft Entra ID SAML Configuration Guide¶
This guide outlines the step-by-step process to configure Microsoft Entra ID as an Identity Provider (IdP) using SAML 2.0 with Hyperview.
You must also be logged in as an Administrator in Hyperview to finish the Hyperview configuration side of the setup.
Prerequisites¶
Permissions: You must have either the Cloud Application Administrator or Application Administrator role in your Entra tenant.
Step 1: Create the Enterprise Application¶
Sign in to the Microsoft Entra admin center.
Navigate to Entra ID > Enterprise apps > All applications.
Select New application at the top of the page.
Click Create your own application.
Name your application “Hyperview”.
Choose Integrate any other application you don’t find in the gallery (Non-gallery).
Click Create and wait for the application to deploy.
Log in to Hyperview and navigate to SAML SSO Configuration (Your Name in the top right → Account Management → SAML SSO Configuration).
Change Data Export Method to Metadata file and Certificate.
Download Metadata and Download Certificate.
Step 2: Configure SAML Single Sign-On¶
In the application’s left-hand navigation menu, click Single sign-on.
Select SAML as the single sign-on method.
Click Upload metadata file and select the metadata file downloaded earlier.
Click Save at the top of the panel.
Scroll down to section 3, SAML Certificates, and click the edit button next to Verification certificates.
Click Require verification certificates.
Click Upload certificate and upload the certificate file downloaded earlier.
Click Save.
Click Token Encryption in the left pane under the security group.
Click Import certificate and upload the certificate file downloaded earlier.
Click the three dots “…” in the certificate row and select Activate token encryption certificate.
Step 3: Link Entra ID to Hyperview¶
Navigate back to Single sign-on in the left pane.
Scroll down to the SAML Certificates section on the SAML setup page.
Copy the App Federation Metadata Url.
Return to your Hyperview application instance as an administrator and navigate to SAML SSO Configuration.
Set Data Import Method to Metadata URL and paste the URL in the Metadata URL field.
Click Submit.
Optionally enter a Provider Name to show that on the login page. Otherwise, the generic Sign in with SSO label is used.
Click Save.
Step 4: Optionally, Assign Users and Test¶
Optional user and group assignments may be required to restrict application access. Please note that this does not grant access to Hyperview unless there is an existing user or a User Provisioning policy for the domain.
Return to Entra ID, navigate to Properties, enable Assignment required, and click Save.
Navigate to Users and groups.
Click Add user/group.
Add users and groups as required.
Test the integration by using a different browser or asking a colleague to test to ensure that SSO is configured properly.
Important
Please do not enforce SAML Authentication for the domain unless you have tested and verified that everything works correctly. Doing so without testing and verification could result in you being locked out of your account.
For more information about configuring SAML with Entra ID, please refer to Microsoft Documentation.