This guide explains how to integrate TimeClock 365 SAML single sign-on (SSO) with Azure Active Directory (Azure AD).
When you integrate TimeClock 365 SAML with Azure AD, you can:
- Control access to TimeClock 365 SAML through Azure AD.
- Allow your users to sign in to TimeClock 365 SAML automatically using their Azure AD accounts.
- Manage your accounts in one central location - the Azure portal.
TimeClock 365 SAML supports SP-initiated SSO and automatic user assignment. This guide sets up and tests Azure AD SSO in a test environment.
Add TimeClock 365 SAML from the gallery
- Sign in to the Azure portal using a work, school, or personal Microsoft account.
- In the left navigation pane, select Azure Active Directory.
- Go to Enterprise Applications, then select All Applications.
- To add a new application, select New application.
- In the "Add from the gallery" section, type TimeClock 365 SAML in the search box.
- Select TimeClock 365 SAML from the results and add the application.
Set up and test Azure AD SSO for TimeClock 365 SAML
Set up and test Azure AD SSO with TimeClock 365 SAML using a test user named B.Simon. To make SSO work, you need to establish a link between an Azure AD user and the related user in TimeClock 365 SAML.
- Set up Azure AD SSO to allow your users to use this feature.
- Create an Azure AD test user to test the Azure AD sign-in with B.Simon.
- Assign the Azure AD test user so B.Simon can use Azure AD sign-in.
- Set up TimeClock 365 SAML SSO to configure the sign-in settings on the application side.
- Create a test user in TimeClock 365 SAML - B.Simon, linked to the Azure AD representation of the user.
- Test SSO to verify the configuration works.
Set up Azure AD SSO
- On the Azure portal's TimeClock 365 SAML application integration page, find Manage and select single sign-on.
- On the single sign-on page, select SAML.
- On the "Set up single sign-on with SAML" page, click the pencil icon next to Basic SAML Configuration to edit the settings.
- In Basic SAML Configuration, enter the following values: in the Sign-on URL text box, type: https://live.timeclock365.com/login
- On the "Set up single sign-on with SAML" page, under the SAML Signing Certificate, click the copy button to copy the App Federation Metadata URL and save it to your computer.
Create an Azure AD test user
- In the left pane of the Azure portal, select Azure Active Directory, select Users, then select All users.
- Select New user at the top of the screen.
- In the user properties, do the following:
- In the Name field, enter B.Simon.
- In the Username field, enter a username in the form [email protected], for example [email protected].
- Select Show password, then note the value shown in the password box.
- Click Create.
Assign the Azure AD test user
- In the Azure portal, select Enterprise Applications, then select All Applications.
- In the applications list, select TimeClock 365 SAML.
- On the application's overview page, find Manage and select Users and groups.
- Select Add user, then select Users and groups in the Add Assignment dialog.
- In the Users and groups dialog, select B.Simon from the user list, then click Select at the bottom of the screen.
- If a role is expected to be assigned to users, you can select it from the Select a role dropdown. If no role has been set up for the application, the "Default Access" role will be selected.
- In the Add Assignment dialog, click Assign.
Set up TimeClock 365 SAML SSO
- Open a new tab and sign in to TimeClock 365 as an administrator.
- Go to Settings -> Company Profile -> SAML tab at the top.
- In the IDP metadata path field, paste the App Federation Metadata URL you copied from the Azure portal.
- Click Update.
Create a test user in TimeClock 365 SAML
- Open a new browser tab and sign in to our site as an administrator.
- Go to Users, then Add new user.
- Provide all the information on the user details page and click Save.
- Click Create to create the test user.
Test SSO
At this stage, test the Azure AD sign-in configuration using one of the following options:
- Click "Test this application" in the Azure portal - this will redirect to the TimeClock 365 SAML sign-on URL, where you can start the sign-in flow.
- Go directly to the TimeClock 365 SAML sign-on URL and start the sign-in flow from there.
- Use Microsoft My Apps - clicking TimeClock 365 SAML in My Apps will redirect to the TimeClock 365 SAML sign-on URL.