Skip to content
English
  • There are no suggestions because the search field is empty.

Signing and encryption SAML SSO Entra ID

Signing

Start by enabling "Require verification certificates" during the Set up Single Sign-On with SAML step of an Enterprise Application. In step 3 of the set up, press edit in the section “Verification certificates (optional)”.

Skärmavbild 2025-03-13 kl. 11.02.32

Select the option "Require verification certificates".

Skärmavbild 2025-03-13 kl. 11.07.50

Download the Federation Metadata XML and re-upload it to Refapp. 

Then download the PEM files, unzip the folder and upload the certificate in the Verification certificates section.

Skärmavbild 2025-03-13 kl. 11.13.00

Skärmavbild 2025-03-13 kl. 11.25.35

Encryption

Turn on “Assertions will be encrypted” in Refapp SAML SSO Settings.

Skärmavbild 2025-03-13 kl. 13.17.45

In Entra, select "Token encryption" in the menu to the left. 

Skärmavbild 2025-03-13 kl. 13.18.32

 

Press "Import Certificate" and upload the same certificate that you downloaded for signing. After uploading the certificate, use the dot-menu to activate encryption.

image (7)