3 ms·
Had a quick look at your docs for integrating with Azure AD SAML https://workos.com/docs/integrations/azure-ad-saml https://workos.com/docs/integrations/azure-a
by duncans 6y ago
Had a quick look at your docs for integrating with Azure AD SAML https://workos.com/docs/integrations/azure-ad-saml https://workos.com/docs/integrations/azure-ad-saml and wondered why you don't make use of SAML metadata URLs that contain all this configuration? For example the signing certificates, ACS, Reply/ACS URL, EntityIDs are all in the metadata xml docs, so you could boil it down to:
* Here's the SP metadata URL - upload it into Azure dashboard here ...
* Grab the "App Federation metadata URL" from the Azure dashboard and paste it into WorkOS here ... (where your app can parse the XML and grab certs, URLs etc)
And you're done.
- grinich 6y agoWe're planning to push all configuration to metadata endpoints for providers who support it. There are additional benefits for refreshing SAML certificates (usually every 5 years) and dynamically adapting to other attributes changing. This will get added to our Admin Portal, which is a pre-built experience for IT admins to configure SSO connections: https://workos.com/docs/admin-portal/guide/introduction https://workos.com/docs/admin-portal/guide/introduction Unfortunately the metadata URL configuration path isn't universally supported. I'm hoping FastFed solves this, but all that is still in working group / pre-RFC. https://openid.net/wg/fastfed/ https://openid.net/wg/fastfed/