PageSourceSearch

https://bambuser.com/docs/assets/js/166285da.a5484e81.js

js bambuser.com collected 2026-09-24 08:27:12 UTC 16,099 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkbambuser_docs||=[]).push([[658],{19633(e,n,i){i.r(n),i.d(n,{assets:()=>a,contentTitle:()=>o,default:()=>h,frontMatter:()=>l,metadata:()=>s,toc:()=>c});const s=JSON.parse('{"id":"samlViaAzure","title":"Set up SAML SSO with Microsoft Azure","description":"Configure SAML 2.0 SSO with Azure AD: non-gallery Enterprise app, entity ID bambuser_saml_service_provider, US/EU reply URLs, claim mapping, group roles.","source":"@site/live/ssoSamlViaAzure.mdx","sourceDirName":".","slug":"/saml-azure","permalink":"/docs/live/saml-azure","draft":false,"unlisted":false,"tags":[],"version":"current","frontMatter":{"id":"samlViaAzure","title":"Set up SAML SSO with Microsoft Azure","description":"Configure SAML 2.0 SSO with Azure AD: non-gallery Enterprise app, entity ID bambuser_saml_service_provider, US/EU reply URLs, claim mapping, group roles.","sidebar_label":"SAML via Azure AD","slug":"saml-azure"},"sidebar":"someSidebars","previous":{"title":"SAML via Okta","permalink":"/docs/live/saml-okta"},"next":{"title":"Custom SAML","permalink":"/docs/live/custom-saml"}}');var r=i(74848),t=i(28453);const l={id:"samlViaAzure",title:"Set up SAML SSO with Microsoft Azure",description:"Configure SAML 2.0 SSO with Azure AD: non-gallery Enterprise app, entity ID bambuser_saml_service_provider, US/EU reply URLs, claim mapping, group roles.",sidebar_label:"SAML via Azure AD",slug:"saml-azure"},o=void 0,a={},c=[{value:"Overview",id:"overview",level:2},{value:"Prerequisites",id:"prerequisites",level:2},{value:"Step 1: Register a New Application in Azure",id:"step-1-register-a-new-application-in-azure",level:2},{value:"Step 2: Configure Single Sign-On",id:"step-2-configure-single-sign-on",level:2},{value:"Step 3: Configure Basic SAML Settings",id:"step-3-configure-basic-saml-settings",level:2},{value:"Step 4: Configure Claims",id:"step-4-configure-claims",level:2},{value:"Step 5: Configure User Assignment",id:"step-5-configure-user-assignment",level:2},{value:"Step 5: Share Configuration with Bambuser",id:"step-5-share-configuration-with-bambuser",level:2},{value:"Required Information",id:"required-information",level:3},{value:"Metadata XML file",id:"metadata-xml-file",level:4},{value:"Step 6: Configure User Access",id:"step-6-configure-user-access",level:2},{value:"Option A: Manual User Management (Default)",id:"option-a-manual-user-management-default",level:3},{value:"Option B: Group-based Management (Recommended)",id:"option-b-group-based-management-recommended",level:3},{value:"Step 6: Test and Verify Your Integration",id:"step-6-test-and-verify-your-integration",level:2},{value:"Support",id:"support",level:2},{value:"Optional: Automated User Provisioning (SCIM)",id:"optional-automated-user-provisioning-scim",level:2}];function d(e){const n={a:"a",admonition:"admonition",code:"code",h2:"h2",h3:"h3",h4:"h4",li:"li",ol:"ol",p:"p",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,t.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.h2,{id:"overview",children:"Overview"}),"\n",(0,r.jsx)(n.p,{children:"This guide provides step-by-step instructions for configuring SAML 2.0 Single Sign-On (SSO) between Microsoft Azure Active Directory and Bambuser Virtual Commerce. This integration allows your organization to manage user authentication through your existing Azure AD infrastructure."}),"\n",(0,r.jsx)(n.admonition,{title:"Recommendation",type:"tip",children:(0,r.jsxs)(n.p,{children:["For a more seamless experience with automated user provisioning, we recommend using our native ",(0,r.jsx)(n.a,{href:"/live/microsoft-sso",children:"Microsoft Azure AD OIDC integration"}),"."]})}),"\n",(0,r.jsx)(n.h2,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Administrative access to Microsoft Azure AD"}),"\n",(0,r.jsx)(n.li,{children:"A verified domain for user email addresses"}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.code,{children:"Manage Users"})," permission in Bambuser dashboard ",(0,r.jsx)("span",{class:"remark-label","data-label":"Optional"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-1-register-a-new-application-in-azure",children:"Step 1: Register a New Application in Azure"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["Sign in to the ",(0,r.jsx)(n.a,{href:"https://portal.azure.com/",children:"Azure Portal"})]}),"\n",(0,r.jsxs)(n.li,{children:["Navigate to ",(0,r.jsx)(n.strong,{children:"Azure Active Directory"})," > ",(0,r.jsx)(n.strong,{children:"Enterprise applications"})]}),"\n",(0,r.jsxs)(n.li,{children:["Click ",(0,r.jsx)(n.strong,{children:"New application"})]}),"\n",(0,r.jsxs)(n.li,{children:["Select ",(0,r.jsx)(n.strong,{children:"Create your own application"})]}),"\n",(0,r.jsxs)(n.li,{children:['Enter a name (e.g., "Bambuser SAML") and  select ',(0,r.jsx)(n.strong,{children:"Integrate any other application you don't find in the gallery (Non-gallery)"})]}),"\n",(0,r.jsxs)(n.li,{children:["Click ",(0,r.jsx)(n.strong,{children:"Create"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-2-configure-single-sign-on",children:"Step 2: Configure Single Sign-On"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In your new application, go to ",(0,r.jsx)(n.strong,{children:"Manage"})," > ",(0,r.jsx)(n.strong,{children:"Single sign-on"})]}),"\n",(0,r.jsxs)(n.li,{children:["Select ",(0,r.jsx)(n.strong,{children:"SAML"})," as the single sign-on method"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-3-configure-basic-saml-settings",children:"Step 3: Configure Basic SAML Settings"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In the ",(0,r.jsx)(n.strong,{children:"Basic SAML Configuration"})," section, click ",(0,r.jsx)(n.strong,{children:"Edit"})]}),"\n",(0,r.jsxs)(n.li,{children:["Enter the following values:","\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Identifier (Entity ID)"}),": ",(0,r.jsx)(n.code,{children:"bambuser_saml_service_provider"})]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Reply URL (Assertion Consumer Service URL)"}),":","\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["US: ",(0,r.jsx)(n.code,{children:"https://svc-prod-us.liveshopping.bambuser.com/functions/auth/sso/saml/callback"})]}),"\n",(0,r.jsxs)(n.li,{children:["EU: ",(0,r.jsx)(n.code,{children:"https://svc-prod-eu.liveshopping.bambuser.com/functions/auth/sso/saml/callback"})]}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["Click ",(0,r.jsx)(n.strong,{children:"Save"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-4-configure-claims",children:"Step 4: Configure Claims"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In the ",(0,r.jsx)(n.strong,{children:"Attributes & Claims"})," section, click ",(0,r.jsx)(n.strong,{children:"Edit"})]}),"\n",(0,r.jsxs)(n.li,{children:["Make sure you have the following claims:","\n",(0,r.jsxs)(n.table,{children:[(0,r.jsx)(n.thead,{children:(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.th,{children:"Claim name"}),(0,r.jsx)(n.th,{children:"Type"}),(0,r.jsx)(n.th,{children:"Value"}),(0,r.jsx)(n.th,{children:"Require?"})]})}),(0,r.jsxs)(n.tbody,{children:[(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"email"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"SAML"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"user.mail"})}),(0,r.jsx)(n.td,{children:"Yes"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"firstName"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"SAML"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"user.givenName"})}),(0,r.jsx)(n.td,{children:"Optional"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"lastName"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"SAML"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"user.surname"})}),(0,r.jsx)(n.td,{children:"Optional"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"nameID"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"SAML"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"user.userPrincipalName"})}),(0,r.jsx)(n.td,{children:"Optional"})]}),(0,r.jsxs)(n.tr,{children:[(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"groups"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"SAML"})}),(0,r.jsx)(n.td,{children:(0,r.jsx)(n.code,{children:"user.groups"})}),(0,r.jsx)(n.td,{children:"Optional"})]})]})]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["Click ",(0,r.jsx)(n.strong,{children:"Save"})]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-5-configure-user-assignment",children:"Step 5: Configure User Assignment"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In the application's ",(0,r.jsx)(n.strong,{children:"Properties"})," section, set ",(0,r.jsx)(n.strong,{children:"User assignment required?"})," to ",(0,r.jsx)(n.strong,{children:"Yes"})]}),"\n",(0,r.jsxs)(n.li,{children:["Go to ",(0,r.jsx)(n.strong,{children:"Users and groups"})," to assign users or groups to the application"]}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-5-share-configuration-with-bambuser",children:"Step 5: Share Configuration with Bambuser"}),"\n",(0,r.jsx)(n.p,{children:"Contact your Bambuser representative and provide the following information:"}),"\n",(0,r.jsx)(n.h3,{id:"required-information",children:"Required Information"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Domain"}),": Your organization's email domain (e.g., ",(0,r.jsx)(n.code,{children:"yourcompany.com"}),")"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"SAML Certificate"}),": Download the Base64 certificate from the **SAML Certificates ** section"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Login URL"}),": Found in the ",(0,r.jsx)(n.strong,{children:"Set up [Application Name]"})," section"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Azure AD Identifier"}),": Found in the ",(0,r.jsx)(n.strong,{children:"Set up [Application Name]"})," section"]}),"\n",(0,r.jsxs)(n.li,{children:[(0,r.jsx)(n.strong,{children:"Logout URL"}),": (Optional) If you want to enable single sign-out"]}),"\n"]}),"\n",(0,r.jsx)(n.h4,{id:"metadata-xml-file",children:"Metadata XML file"}),"\n",(0,r.jsx)(n.p,{children:"Alternatively, you can share the federation metadata XML file from the **SAML Certificates ** section. This file will include all information needed to configure SAML SSO."}),"\n",(0,r.jsx)(n.h2,{id:"step-6-configure-user-access",children:"Step 6: Configure User Acce
1ss"}),"\n",(0,r.jsx)(n.h3,{id:"option-a-manual-user-management-default",children:"Option A: Manual User Management (Default)"}),"\n",(0,r.jsx)(n.p,{children:"Manage users/roles manually in the Bambuser dashboard."}),"\n",(0,r.jsx)(n.p,{children:"For each new user:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Add them to your Azure AD"}),"\n",(0,r.jsx)(n.li,{children:"Manually create their account in the Bambuser dashboard"}),"\n",(0,r.jsx)(n.li,{children:"Assign appropriate roles and permissions on the Bambuser dashboard"}),"\n"]}),"\n",(0,r.jsx)(n.h3,{id:"option-b-group-based-management-recommended",children:"Option B: Group-based Management (Recommended)"}),"\n",(0,r.jsx)(n.p,{children:"Manage users/roles through groups in Azure AD:"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["In Azure AD, create groups for different permission levels (e.g., ",(0,r.jsx)(n.code,{children:"bambuser-owner"}),", ",(0,r.jsx)(n.code,{children:"bambuser-moderator"}),")"]}),"\n",(0,r.jsx)(n.li,{children:"Share the group names with your Bambuser representative"}),"\n",(0,r.jsx)(n.li,{children:"Bambuser team will map these groups to existing roles in Bambuser ecosystem"}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"step-6-test-and-verify-your-integration",children:"Step 6: Test and Verify Your Integration"}),"\n",(0,r.jsx)(n.p,{children:"Once the SAML configuration is completed by Bambuser on your workspace, test the integration:"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Test authentication flow"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Navigate to Bambuser dashboard ",(0,r.jsx)(n.a,{href:"https://lcx.bambuser.com",children:(0,r.jsx)("span",{class:"remark-label","data-label":"Global Login"})})," ",(0,r.jsx)(n.a,{href:"https://lcx-eu.bambuser.com",children:(0,r.jsx)("span",{class:"remark-label","data-label":"EU Login"})})]}),"\n",(0,r.jsx)(n.li,{children:"Enter a test user's email"}),"\n",(0,r.jsx)(n.li,{children:"Verify redirection to Azure AD login"}),"\n",(0,r.jsx)(n.li,{children:"Complete authentication"}),"\n",(0,r.jsx)(n.li,{children:"Confirm successful login to Bambuser"}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.li,{children:["\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.strong,{children:"Verify user attributes"})}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Check that user details (name, email) are correctly passed"}),"\n",(0,r.jsx)(n.li,{children:"Verify role assignments"}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,r.jsxs)(n.admonition,{title:"Test on Staging",type:"note",children:[(0,r.jsx)(n.p,{children:"If you have a separate Bambuser workspace for testing, you can ask us to set up a separate SAML integration for testing."}),(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsxs)(n.li,{children:["Use a test domain (e.g., ",(0,r.jsx)(n.code,{children:"test.yourcompany.com"}),") to avoid impacting production users"]}),"\n",(0,r.jsx)(n.li,{children:"Create test users in Azure AD"}),"\n"]})]}),"\n",(0,r.jsx)(n.h2,{id:"support",children:"Support"}),"\n",(0,r.jsx)(n.p,{children:"For assistance, contact:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Your dedicated Bambuser representative"}),"\n",(0,r.jsxs)(n.li,{children:["Or our support team at ",(0,r.jsx)(n.a,{href:"mailto:[email protected]",children:"[email protected]"}),' (Subject: "Azure SAML Integration")']}),"\n"]}),"\n",(0,r.jsx)(n.h2,{id:"optional-automated-user-provisioning-scim",children:"Optional: Automated User Provisioning (SCIM)"}),"\n",(0,r.jsxs)(n.p,{children:["For organizations requiring automated user provisioning and deprovisioning, you can implement a custom SCIM (System for Cross-domain Identity Management) integration using our ",(0,r.jsx)(n.a,{href:"https://liveshopping-api.bambuser.com/v1/docs/api/one-to-many#section/Authentication",children:"public API"}),". This allows for:"]}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Automatic user creation when added to your Azure AD"}),"\n",(0,r.jsx)(n.li,{children:"Role and permission synchronization"}),"\n",(0,r.jsx)(n.li,{children:"Immediate access revocation when users are deprovisioned"}),"\n"]}),"\n",(0,r.jsx)(n.p,{children:"To implement SCIM integration:"}),"\n",(0,r.jsxs)(n.ol,{children:["\n",(0,r.jsx)(n.li,{children:"Review our API documentation for user management endpoints"}),"\n",(0,r.jsx)(n.li,{children:"Develop a SCIM service that interfaces with Azure AD"}),"\n",(0,r.jsx)(n.li,{children:"Contact support to enable the necessary API access"}),"\n"]}),"\n",(0,r.jsx)(n.admonition,{type:"note",children:(0,r.jsx)(n.p,{children:"SCIM implementation requires development resources and is recommended for organizations with significant user management needs."})})]})}function h(e={}){const{wrapper:n}={...(0,t.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}},28453(e,n,i){i.d(n,{R:()=>l,x:()=>o});var s=i(96540);const r={},t=s.createContext(r);function l(e){const n=s.useContext(t);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function o(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:l(e.components),s.createElement(t.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.