Note: This guide is specifically tailored to users subscribed to an Enterprise plan.
This guide will walk you through how to configure Azure Active Directory (AD) in order to give users in your Organization access to the Magicul services via SSO. In this guide we will use SAML-base Single Sign On.
Configuring SSO always requires our Support Team to add your Azure AD configuration details. In this guide we will setup everything so you can forward the necessary details to our team to finalize the integration.
Step 1: Open the Azure AD in the Azure Portal
Open the Azure Portal via https://portal.azure.com
Then select "Azure Activate Directory" from the list of services. Alternatively you can use the search bar at the top to search for "Azure Active Directory".
Once you have the Azure AD dashboard open click on "Enterprise applications" in the left hand panel. This will open the settings page to configure new applications.
Now click on "New Application" in the main section to create a new application for our SAML SSO application.
This will show you an overview of application that are available in the Azure AD Gallery. You can ignore that, simply click on "Create your own application" at the very top.
Type in a name for the application (for example "Magicul SAML SSO") and select "Integrate any other application you don't find in the gallery (Non-gallery)".
This will open the details page of the Azure AD application.
Afterwards click on "Single sign-on" in the left hand panel.
Select "SAML" as the Single Sign-On method.
This will bring you to the configuration page of the SAML method.
Click on "Edit" for the "Basic SAML Configuration" to edit the details.
NOTE: The values for the Identifier and Reply URL should be provided by the Technical Support of Magicul.
The Identifier (Entity ID) will be:
urn:auth0:xd2sketch:Magicul-SSO-YOURCOMPANYReply URL (Assertion Consumer Service URL):
https://xd2sketch.us.auth0.com/login/callback?connection=Magicul-SSO-YOURCOMPANYSign on URL:
https://xd2sketch.us.auth0.com/samlp/GKnSTNrfPRobgPQHYh5erSpqqwpHiyyH
The other values can be left empty.
Afterwards click on "Save" at the top and then close the window by clicking on the "X" icon in the top right corner.
Next edit "Attributes & Claims" by clicking on the "Edit" button in the 2nd section.
In there we only need to configure one value and that will be the email field and the Unique User Identifier which will map to the user email field. Note that in Azure AD mail is the equivalent for email.
Thats almost it. Afterwards you simply need to download the SAML Certificate and the copy the Login URL and forward that to the Technical Support to finalize the integration.










