Skip to main content
Single sign-on (SSO) lets your users sign in to Guardhouse with their existing Microsoft work accounts. You set it up by creating a SAML enterprise application in Microsoft Entra ID (formerly Azure Active Directory) and exchanging a few configuration values with Guardhouse.

Before you begin

Setting up SSO is a joint process between you and Guardhouse.

What Guardhouse provides

Guardhouse supplies the values you need for the SAML configuration:
  • Identifier (Entity ID)
  • Reply URL (Assertion Consumer Service URL)
  • Sign-on URL
  • Logout URL

What you provide to Guardhouse

Send Guardhouse the following details:
  • Your Microsoft tenant ID. In the Azure portal, search for Tenant ID within Microsoft Entra ID.
  • Your preferred company name. Guardhouse uses this in the custom sign-on URL for your application.
    Guardhouse sign-in page showing a company name above a Continue button with the Microsoft logo

    The company name appears on your custom Guardhouse sign-in page.

  • Your preferred domain. This is the domain your users enter when they sign in to Guardhouse.
    Guardhouse sign-in page with a domain input field and a Continue button

    Users enter your domain on the Guardhouse sign-in page.

  • Your security groups and their company entities (multiple-company setups only). Provide a list of your Azure security groups and the Guardhouse company entity each one maps to. See Multiple-company setup.

Step 1: Create an enterprise application

  1. Sign in to the Azure portal with an administrator account.
  2. Under Azure services, select Enterprise applications.
    Azure services list with Enterprise applications highlighted
  3. Click New application.
    Enterprise applications page with New application highlighted in the toolbar
  4. Click Create your own application.
  5. Enter a name for the application, for example YourApp SSO.
  6. Select Integrate any other application you don’t find in the gallery (Non-gallery).
    Create your own application panel with an app name entered and the Non-gallery option selected
  7. Click Create.

Step 2: Configure SAML single sign-on

  1. In your new application, select Single sign-on.
  2. Select SAML as the single sign-on method.
    Select a single sign-on method page with the SAML option highlighted
  3. In the Basic SAML Configuration section, click Edit.
  4. Enter the values that Guardhouse provided:
    • Identifier (Entity ID): the unique identifier for your application.
    • Reply URL (Assertion Consumer Service URL): the endpoint that receives SAML assertions from Microsoft Entra ID.
    • Sign on URL: the direct sign-in URL for your application.
    • Logout Url: the endpoint users are redirected to after they sign out.
    SAML-based Sign-on page showing the Basic SAML Configuration section with Identifier, Reply URL, Sign on URL, Relay State, and Logout URL fields
  5. Click Save.
Leave the other sections on the SAML-based Sign-on page (Attributes & Claims, SAML Certificates, and Set up) at their default settings. For a multiple-company setup, you add a group claim to Attributes & Claims in Step 3.

Step 3: Assign users and groups

Choose the setup that matches your organization:
  • Single-company setup: all your users belong to one Guardhouse company.
  • Multiple-company setup: your users belong to different Guardhouse company entities, and Guardhouse uses Azure security groups to map each user to the right one.

Single-company setup

  1. In the Azure portal, open your enterprise application.
  2. Select Users and groups.
  3. Click Add user/group.
    Users and groups page for the enterprise application with Add user/group in the toolbar
  4. Select the users or groups that should have access to Guardhouse.
  5. Optionally, assign a role if your application uses role-based access.
  6. Review your selections, then click Assign.
Assign only authorized users and groups to the application. Anyone you assign can sign in to Guardhouse.

Multiple-company setup

Create security groups

  1. Create a security group for each company, either in Azure or on-premises.
  2. Add the user accounts to their respective groups.
  3. Send Guardhouse the list of groups so they can map each one to the correct company entity.
For example:

Assign the groups to the application

  1. In the Azure portal, open your enterprise application.
  2. Select Users and groups.
  3. Click Add user/group.
    Users and groups page for the enterprise application with Add user/group in the toolbar
  4. Select the security groups you created.
  5. Optionally, assign a role if your application uses role-based access.
  6. Review your selections, then click Assign.
Assign only authorized users and groups to the application. Anyone you assign can sign in to Guardhouse.

Add a group claim

The group claim tells Guardhouse which security groups a user belongs to.
  1. Select Single sign-on, then click Edit in the Attributes & Claims section.
    Attributes & Claims section on the SAML-based Sign-on page with the Edit button
  2. Click Add a group claim.
    Attributes & Claims page with Add a group claim highlighted
  3. Under Which groups associated with the user should be returned in the claim?, select Groups assigned to the application.
  4. Click Save.
    Group Claims panel with Groups assigned to the application selected and Source attribute set to Group ID
  5. Confirm that a groups claim now appears in the list.
    Attributes & Claims page listing the new groups claim with the value user.groups [ApplicationGroup]
    The claim also appears in the Attributes & Claims summary on the SAML-based Sign-on page.
    Attributes & Claims summary showing groups mapped to user.groups