Configure an identity provider for SSO
Add a SAML or Open ID identity provider in SSO Management and set it as active, so account users sign in to Azion Console with single sign-on.
You can connect an external identity provider (IdP) to your account in SSO Management of Azion Console, so account users sign in with their corporate credentials. This page covers the Azion side for any provider. For the provider side of Google, Microsoft Entra, or Okta, refer to Configure Google SAML for SSO, Configure Microsoft Entra SAML for SSO, or Configure Okta SAML for SSO. For how single sign-on works, refer to Single Sign-On.
Prerequisites
- An Enterprise plan for the account.
- Access to Azion Console as an Account owner. Only an Account owner chooses between the Azion login and an external IdP for the users of the account. To sign in, refer to Access Azion Console.
- An application for Azion in your IdP, and the values it issues for the protocol you choose.
Add the identity provider
The Create Identity Provider form takes one protocol, SAML or Open ID, and the values your IdP issued for it.
To add the identity provider in Azion Console:
Access Azion Console and, in the account menu, select SSO Management. The Identity Providers list opens.
Select Add Identity Provider. The Create Identity Provider form opens.
In Select the Identity Provider, select SAML or Open ID.
In the General section, enter a Name. For example: Corporate IdP.
For SAML, fill in the SAML Configuration section: Identity provider’s Entity ID URI, Sign-in URL, and X-509 Certificate.
For Open ID, fill in the Open ID Provider Configuration section: Client ID, Client Secret, Authorization URL, Token URL, UserInfo URL, Scopes, and Response Mode.
The identity provider appears in the Identity Providers list, with its Name and Protocol. It is not in use until you set it as active.
Copy the Azion values to your IdP
A SAML application in your IdP needs two values that Azion generates for the identity provider: Service Provider’s Entity ID URI and Assertion Consumer Service URL. Both are in the SAML Configuration section of the saved identity provider.
To copy the values:
In the Identity Providers list, select the identity provider. The Edit Identity Provider form opens.
Copy Service Provider’s Entity ID URI and Assertion Consumer Service URL, and enter them in your IdP application.
Your IdP application now points at Azion. The provider pages for Google, Microsoft Entra, and Okta name the field that takes each value.
Set the identity provider as active
Activate the identity provider only after your IdP application carries the Azion values. Every user of the account must also exist in Azion with the same email, or the sign-in fails. For more information, refer to Manage users.
To activate the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
In the row of the identity provider, select Set as active.
Every user of the account, except the Account owner, signs in to Azion Console through the IdP. While the IdP is active, the IdP verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.