Service Provider (SP) Initiated SAML Authentication Flow
SqlDBM offers Service Provider (SP) Initiated SAML Authentication for a variety of Identity Providers (IdPs). The diagram below illustrates the request workflow.
SSO Setup Steps
For those who wish to download our Metadata to pre-populate the basic SAML configurations into Azure, please download the SP Metadata. Otherwise, follow the steps below to setup your SSO Application:
Create Application in Azure Active Directory
Navigate to the Azure Active Directory portal
Go to ‘Enterprise applications’ → ‘New application’ → ‘Create your own application’
Name the application “SqlDBM”
Select “Integrate any other application you don’t find in the gallery”
Assign Application to Users
Assign the app to Azure AD users, ensuring the admin account for your subscription is included
Set up SAML
In the app settings, go to "Set up single sign-on" and choose "SAML".
Configure the following
Basic SAML Configuration
Identifier (Entity ID):
https://sqldbm.com/Saml2
Reply URL:
https://sqldbm.com/AzureActiveDirectory/Saml2/Acs
Sign on URL: leave blank
Relay state: leave blank
Logout Url:
https://sqldbm.com/AzureActiveDirectory/Saml2/Logout
Setup Claims:
Email
This should correspond to the user’s email address
Claim type should match either of the following (case sensitive)
Email
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
Name
This will populate the users display name in SqlDBM
Claim type should match (case sensitive)
Name
Submit a Request to Enable SSO
Once your team has completed the setup steps mentioned above, please visit the support portal at support.sqldbm.com and open a support ticket with the following information
App Federation Metadata Url
What to expect once you have submitted a ticket:
The support team will review the information shared
Once the information is verified, your SSO will be enabled on the following Tuesday or Thursday
After Enabling SSO
For new users
Sign up with a username and password
Log in using your username and password
Accept the invitation to join your organization by clicking the link in your invitation email.
Visit your subscription page to confirm that you accepted the invitation
Your account will now be linked to the subscription
Log out and continue to the next section
For existing subscription users
Log in using SSO by selecting the appropriate IdP from the options provided
To access SSO, use the icons on the Sign-In page. If your provider isn’t listed, click the three dots to find the correct IdP.