Skip to main content

Microsoft Entra (formerly Azure AD)

Create a custom SAML application within Microsoft Entra

Paige Ip avatar
Written by Paige Ip
Updated over a month ago

Add From the Entra Gallery (OIDC)

There are a few simple configurations that need to take place within Highway to allow installation of the published Entra Gallery application to your Entra tenant. Please coordinate with your Technical Sales Engineer at Highway to complete this installation.

Add the Enterprise Application

  1. Sign in to the Microsoft Entra admin center with a Cloud Application Administrator, Application Administrator, or Global Administrator role.

  2. In the left navigation menu, go to Entra ID > Enterprise apps.

  3. Click + New application.

  4. In the Browse Microsoft Entra App Gallery page, search Highway.

  5. Select the Highway application with the Highway "H" logo.

Watch your step!

Make sure you're signed out of the Highway broker portal before proceeding with the next step.

  1. Select the Create/Sign-In button which will redirect you into Highway.

  2. You'll be required to enter your email address and click continue on the Highway sign in portal.

  3. Highway will redirect you back to Entra to review Permissions Requested. Read and accept to install the application to your tenant.

  4. After accepting permissions, you'll be signed into Highway. Navigate back to Entra and in the menu, go to Entra ID > Enterprise apps.

  5. Confirm the Highway application shows as installed and has application ID: f3b64aa4-3619-400c-b13f-7283ca62f6c0

Assign Users and Groups

After the application is configured, you must assign users or groups to it to grant them access.

  1. In the application's management menu, select Users and groups.

  2. Click + Add user/group.

  3. On the Add Assignment pane, click None Selected under Users and groups.

  4. Select the users or groups you want to assign to the application and click Select.

  5. Optionally, select a role for the users or groups if the application has defined roles.

  6. Click Assign. Only users assigned to this application will be able to access it through your Entra authentication.

  7. Lastly, navigate to Enterprise Apps > Highway > Properties > Assignment required to enforce users to be assigned to the application to authenticate into Highway.

Once configured, let your Technical Sales Engineer at Highway know when you plan to enforce SSO for Highway through the configured Entra application.


Add a Custom SAML App

Add the Enterprise Application

  1. Sign in to the Microsoft Entra admin center with a Cloud Application Administrator, Application Administrator, or Global Administrator role.

  2. In the left navigation menu, go to Entra ID > Enterprise apps.

  3. Click + New application.

  4. Select Create your own application.

  5. Give your application a name (Highway SAML is a crowd favorite) and select Integrate any other application you don't find in the gallery (Non-gallery).

  6. Click Create.

Configure Single Sign-On (SSO)

  1. On the new application's overview page, go to Manage > Single sign-on.

  2. Choose SAML as the single sign-on method.

  3. In the Basic SAML Configuration section, click the Edit pencil icon.

  4. Enter the following information:

Variables

Value

Identifier (Entity ID)

https://highway.com/identity/saml/metadata

Reply URL(Assertion Consumer Service URL)

https://highway.com/identity/saml/consume

Sign on URL

https://highway.com/broker/login

Attributes and Claims

Map 'givenname' to 'user.givenname'Map 'surname' to 'user.surname'Map 'emailaddress' to 'user.mail

Click Save

Download the XML Metadata File

  1. After saving the SAML configuration, scroll down to SAML Signing Certificate.

  2. Next to Federation Metadata XML, click the Download link.

  3. Send the downloaded XML file to your Technical Sales Engineer contact at Highway.

Assign Users and Groups

After the application is configured, you must assign users or groups to it to grant them access.

  1. In the application's management menu, select Users and groups.

  2. Click + Add user/group.

  3. On the Add Assignment pane, click None Selected under Users and groups.

  4. Select the users or groups you want to assign to the application and click Select.

  5. Optionally, select a role for the users or groups if the application has defined roles.

  6. Click Assign. Only users assigned to this application will be able to access it through your Entra authentication.

Once configured, let your Technical Sales Engineer at Highway know when you plan to enforce SSO for Highway through the configured Entra application.


Additional Resources from Microsoft

Did this answer your question?