Here we will take you through the steps on how to configure Humand as a SAML-based application in Azure Active Directory, enabling secure and seamless Single Sign-On (SSO) for your users.
Creating a New Enterprise Application
1. Sign in to the Azure Portal.
2. In the top search bar, type Enterprise Applications, and click the result.
3. Click + New Application.
4. Select Create your own application.
5. Enter an application name (e.g., Humand-EndUser-SSO).
6. Choose: Integrate any other application you don’t find in the gallery (Non-gallery).
7. Click Create.
Configuring SAML-Based Sign-In
From the application overview page, click Set up single sign-on.
- Choose SAML as the sign-on method.
Basic SAML Configuration
Click Edit under the Basic SAML Configuration section and fill in the following fields:
Make sure you have your INSTANCE_ID value, which represents your Humand community. Contact your Humand Onboarding Leader if you don’t have it.
FIELD VALUE Identifier (Entity ID) https://api-prod.humand.co/api/v1/sso-saml/INSTANCE_ ID Reply URL (ACS) https://api-prod.humand.co/api/v1/sso-saml/callback? to=INSTANCE_ID
If you also want to enable SSO for the Humand Admin/Back Office site, follow the same process outlined above with the updated URLs below:
FIELD VALUE Identifier (Entity ID) https://api-prod.humand.co/api/v1/backoffice/sso-saml/callback?to=INST
ANCE_IDReply URL (ACS) https://api-prod.humand.co/api/v1/backoffice/sso-saml/INSTANCE_ID
Federation Metadata
1. Download the Federation Metadata XML.
Send this URL to: help@humand.co
CC: your Humand Onboarding Leader or Account Manager.
Assigning Users and Groups
1. Go to the Users and Groups section.
2. Click + Add user/group.
3. Select the users or Azure AD groups who should have access to Humand.
4. Click Assign.
Final Considerations
- If you encounter any issues while configuring Humand in your Azure tenant, please reach out to help@humand.co
- Once both sides (Humand and your team) have completed the configuration, Humand will notify you to begin the SSO testing process.
- By default, all assigned users will be routed through Single Sign-On (SSO).
- If any users need to bypass SSO and log in using a username and password, please send a list of those users to help@humand.co. This ensures proper access is granted via traditional login credentials.