Skip to content
  • There are no suggestions because the search field is empty.

Configure SSO with Microsoft Entra ID

Use Microsoft Entra ID for SSO to increase security and save time.

You can use Microsoft Entra ID for Single sign-on, and your users will be able to access Qminder Dashboard without needing to remember another password.

Installation

Microsoft Entra ID

Log in to one of the following:

Then follow these steps to set up Qminder application in Microsoft Entra:
  1. Navigate to Enterprise appsNew application
    1 Entra - Enterprise apps
  2. Search for Qminder and select the result

    2 Entra - Enterprise apps search Qminder
  3. Click on "Create"
    3 Entra - Enterprise apps Qminder Create
  4. From left navigation choose Single sign-on and then select SAML as the method
    4 Entra - Qminder SSO

  5. There should be a dialog prompting to save required SAML settings. Click Yes.
    Or alternatively, Edit Basic SAML Configuration manually with the following values:
    1. Identifier (Entity ID): https://dashboard.qminder.com/saml/metadata
    2. Reply URL: https://dashboard.qminder.com/saml/SSO
    3. Sign on URL: Leave empty!
    5 Entra - SAML Entity ID
  6. Copy the App Federation Metadata Url and Microsoft Entra Identifier
    6 Entra - Copy SAML details
  7. Go to Users and groups and assign users (including yourself) who can access this application.
  8. Go to Properties and make sure Visible to users? is enabled.

Qminder Dashboard

  1. In Qminder, navigate to bottom-left menu → Integrations and choose Install under Microsoft Entra ID
    7 Qminder - Integrations
  2. Click on Install button in the top right
    8 Qminder - Entra Install
  3. Paste Microsoft Entra Identifier and App Federation Metadata Url that you previously copied from Microsoft Entra.
    Don't forget to press Save
    9 Qminder - Entra config

Testing logging in from Microsoft Entra ID to Qminder

Now you can initiate login from Microsoft Entra ID. This is also known as IdP-initiated SAML login, where IdP stands for Identity Provider, which in this case is Microsoft Entra ID.

  1. Log out from https://dashboard.qminder.com/
  2. In Microsoft Entra, go back to Single sign-on of the Qminder app and from there choose Test this application
    10 Entra - Test this app
  3. And then press Test sign in. If Qminder opens and is logged in, then it works!
    11 Entra - Test test
  4. If you want another user to be able to test logging in, they can do so by visiting https://myapps.microsoft.com/ and choosing Qminder.
    12 Entra - myapps.microsoft.com
    If they don't see Qminder app there, go to Properties and make sure Visible to users? is enabled.

Logging in from Qminder login screen using Microsoft Entra ID

If you have verified that logging in worked in one of the previous steps, then you can contact us to enable logging in from the Qminder login screen using Microsoft Entra ID. This is also known as SP-initiated SAML login, where SP stands for Service Provider, which in this case is Qminder.

Once we enable it, the following will happen:

  • Anyone entering a username with @yourcorp.com email address will not be able to enter a password anymore, and will instead see a passwordless login screen.
  • Users who are not registered to Qminder yet, will automatically be created a new Qminder user. This is also known as SAML JIT (Just-in-time).
    New users will automatically have clerk permission in every location. The account owner or one of the account administrators needs to set more specific permissions directly inside Qminder.

Notes

  • No SCIM (System for Cross-domain Identity Management) support.
    This means that even though new users are automatically created through SAML JIT, then removing users from Qminder and assigning user roles has to be done through Qminder.