Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Community
Community
Notifications
close
  • Forums
  • Knowledge Center
  • Events & Webinars
  • Ideas
  • Blogs
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register
Sustainability
Sustainability

Join our "Ask Me About" community webinar on May 20th at 9 AM CET and 5 PM CET to explore cybersecurity and monitoring for Data Center and edge IT. Learn about market trends, cutting-edge technologies, and best practices from industry experts.
Register and secure your Critical IT infrastructure

EBO SAML Single Sign On Integration Guide with Azure

Building Automation Knowledge Base

Schneider Electric Building Automation Knowledge Base is a self-service resource to answer all your questions about EcoStruxure Building suite, Andover Continuum, Satchwell, TAC…

cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 
  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Building Automation Knowledge Base
  • EBO SAML Single Sign On Integration Guide with Azure
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • StephenYang
    StephenYang

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Building Automation Knowledge Base
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
2 Likes
2823 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

EBO SAML Single Sign On Integration Guide with Azure

Admiral StephenYang Admiral
‎2024-06-19 11:43 AM

on ‎2024-06-19 11:43 AM

Warning

Potential for Data Loss: The steps detailed in the resolution of this article may result in a loss of critical data if not performed properly. Before beginning these steps, make sure all important data is backed up in the event of data loss. If you are unsure or unfamiliar with any complex steps detailed in this article, please contact Product Support for assistance.


Issue

Need to setup SAML SSO with Azure EntraID

Product Line

EcoStruxure Building Operation

Environment

  • Building Operation Workstation
  • Azure

Cause

The SAML configuration requires details setup

Resolution

Part 1: EBO configuration

Creating and Configuring the SAML Configuration Object

To create and configure a SAML configuration object.

  1. In WorkStation, in the System Tree pane, expand the System folder.
  2. Expand the Federated Authentication folder.
  3. Select the SAML Authenticator object.
  4. On the File menu, click New object.
  5. Select SAML Configuration.
  6. Enter a name, path, and description on the object you want to create.
  7. Click Create.
  8. Configure the settings.
    StephenYang_0-1718731623263.png

Enabling Federated Authentication

To enable federated authentication

  1. In WorkStation, in the System Tree pane, select the EcoStruxure BMS server you want to configure.
  2. Click the Control Panel tab.
  3. Click Security Settings.
  4. Select Enable federated authentication.
  5. Click the Save button.
    StephenYang_2-1718731836201.png

Configure SAML Configuration object

Service Provider
To configure the service provider.

  1. In WorkStation, in the System Tree pane, click the SAML Configuration object.
  2. Click the Service Provider Settings tab.
  3. Configure the settings.
    StephenYang_3-1718732066360.png

Identity Provider

To configure the identity provider.

  1. In WorkStation, in the System Tree panel, click the SAML Configuration object.
  2. Click the Identity Provider Settings tab.
  3. Configure the settings.
    StephenYang_4-1718732092260.png

Configuring the Security
To configure the security.

  1. In WorkStation, in the System Tree pane, click the SAML Configuration object.
  2. Click the Security Settings tab.
  3. Configure the settings.
    StephenYang_5-1718732158992.png

Create and configure domains
Create and configure a domain to be used for Federated Authentication.

  1. Create a Domains
    StephenYang_6-1718732240373.png
  2. Create a group
    StephenYang_7-1718732327345.png
  3. Configure the permission for the group
    StephenYang_8-1718732375567.png

Part 2: Azure Configuration

Login to https://azure.microsoft.com/

Create SAML application under Entra ID

  1. Click Microsoft Entra ID
    StephenYang_9-1718398302434.jpeg
  1. Click Enterprise Application
    StephenYang_10-1718398302441.jpeg
  2. Select Create your down application
    Enter the name of the App
    Select “Integrate any other application you don’t find in the gallery (Non-gallery)”StephenYang_11-1718398302448.png
  3. An Enterprise Application is created with the nameStephenYang_12-1718398302452.jpeg

Create a group

  1. Select Groups
    StephenYang_13-1718398302456.png
  2. Click New Group
    StephenYang_14-1718398302460.png
  3. Select “Microsoft 365” for the Group type
    Enter the name of the group, the “Group name” must match the Domains Groups name in EBO.
    StephenYang_2-1718732913397.png
  1. Add Owners and Members to the group
    StephenYang_16-1718398302465.png

Configure Entra ID

  1. Select Assign users and groups in the Enterprise Application OverviewStephenYang_17-1718398302471.jpeg
  2. Select Add user/group then click Assign
    StephenYang_18-1718398302474.png
  3. The selected group is under the applicationStephenYang_19-1718398302477.png
  4. Select Set up single sign on in the Enterprise Application Overview
  5. Under Basic SAML configuration
    Enter the information from EBO SAML Authenticator Basic Tab
    The Sign on URL is Base URL
    The Identifier is Entity ID
    The Reply URL is AAssertion Consumer Service URL
    StephenYang_20-1718398302496.png
  6. Click on Edit from Attributes & Claims
    StephenYang_21-1718398302498.png
  7. Click on “Add a group claim”
    Select Groups assigned to the application
    Select Cloud-only group display names under Source attribute
    update the “Unique User Identifier” Value to user.displayname
    StephenYang_22-1718398302501.png
  8. Download the “Federation Metadata XML” certificateStephenYang_1-1718732728341.png
  9. Open the XML file and find the line with certificate, it will start with <XXXXCertificate>StephenYang_24-1718398302503.png
  1. Copy the string between the two brackets and paste it in Public key certificate under Identity Provider Settings
    StephenYang_0-1718732607993.png
  2. Copy the Entity id and Single Sign On Service URL from Azure to EBO.
    The Entity Id is Microsoft Entra Identifier.
    The Single Sign On Service URL is Login URL.

Part 3: Testing

Test Single Sign On

  1. Go to Webstation by entering the SmartX Server network address.
  2. Click on Log on with SSO
    StephenYang_26-1718398302554.png
  1. Select the account within the Azure Group
    StephenYang_27-1718398302556.jpeg
  1. Successful login screen
    StephenYang_28-1718398302559.png
Labels (1)
Labels:
  • EcoStruxure Building Operation
Attachments
Tags (1)
  • Find more articles tagged with:
  • StephenYang24
Was this article helpful? Yes No
100% helpful (2/2)

Link copied. Please paste this link to share this article on your social media post.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support
Brand-Logo
Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2025 Schneider Electric

This is a heading

With achievable small steps, users progress and continually feel satisfaction in task accomplishment.

Usetiful Onboarding Checklist remembers the progress of every user, allowing them to take bite-sized journeys and continue where they left.

of