You can use single sign-on using SAML or Azure AD to authenticate workbench members.
Workbench members are identified within Atomic by a unique email address, supplied by your authentication provider, as part of the authentication flow.
To use SAML SSO with Atomic, you'll need to set up a custom SAML application in your authentication provider, which includes the user’s email address in an attribute.
Contact us for the Identifier and Reply URL details.
Once set up, contact Atomic with the following:
- The IdP metadata XML file for the SAML application
- The name of the SAML attribute which contains the user's email. (For example
- The user's email should be provided in lowercase
Once we have this file, we'll configure our system. Then, your users can choose SSO from the Workbench login screen, enter your organization id, and authentication will be delegated to your provider.
Note, a unique email address must be provided as a SAML attribute, so that users can be identified within Atomic. When logging in with SSO for the first time, user details will be merged with any existing workbench account for the same email address.
Contact us for the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) details.
Then, set up a new enterprise application in Azure:
- Sign in to the Azure portal.
- On the left navigation pane, select the Azure Active Directory service.
- Navigate to Enterprise Applications and then select All Applications.
- To add a new application, select New application.
Create your own application. Enter a name for the application, select
Integrate any other application you don't find in the gallery (Non-gallery), and then click Create.
- Once the application is created, add Users and groups to the application.
- From the navigation pane, go to Single sign-on and click the SAML tile.
- In the SAML-based sign-on page, find the SAML Signing Certificate section and download the Federation Metadata XML.
- Go to Azure AD > Your application > Single Sign-on > Basic SAML Configuration section > Edit
- Confirm email claims match this url:
- Send the Federation Metadata XML file to Atomic (downloaded in step 8) and let us know if the email claims match (what you checked in step 10). Contact us.
- Atomic will then configure the Atomic side and provide a login url where you can test out the integration.