This basic guide shows how to configure Azure for Admin SSO with uStudio Platform. Please note that this guide may not cover everything your organization may want to set up.
Create your Azure Enterprise Application
- Select Enterprise applications when managing Microsoft Azure (Entra ID) applications.
- Select All Applications.
- Click + New application.
- Click + Create your own application.
- Enter your application's name (i.e. uStudio Admin). Then, click Create.
Configure Single Sign-on with SAML
-
Select Single sign-on and click Edit on Basic SAML Configuration.
Enter the following information:
-
- Entity ID as https://login.ustudio.com/auth/realms/platform-users/broker/companycode/endpoint where companycode is replaced by your Company Code in all lowercase characters (i.e. ustudio).
- Assertion Consumer URL as https://login.ustudio.com/auth/realms/platform-users/broker/companycode/endpoint where companycode is replaced by your Company Code in all lowercase characters (i.e. ustudio).
- (Optional) Sign on URL as https://podcast-admin.ustudio.com/ for Podcast Content Management Console (CMC) or https://app.ustudio.com/ for Platform. We only support Service Provider initiated requests.
- Click Save.
- Click Edit on Attributes & Claims. By default you will see these settings below.
- Under Additional claims, click the ellipses (...) on the name claim and Delete it.
- Click the emailaddress claim to edit as follows:
- Set Name to email.
- Clear out the Namespace.
- Set Name format to Unspecified.
- Click Save.
- Click the givenname claim to edit as follows:
- Set Name to given_name.
- Clear out the Namespace.
- Set Name format to Unspecified.
- Click Save.
- Click the surname claim to edit as follows:
- Set Name to family_name.
- Clear out the Namespace.
- Set Name format to Unspecified.
- Click Save.
-
Now, your Attributes & Claims should look like these settings below.
-
Under SAML Certificates and Set up <App>, please provide support@ustudio.com with your App Federation Metadata URL or the XML file itself. At the very least, we need your X509 Certificate and Sign-on URL.
Assign Users and Groups
- Select Users and groups from the left-hand panel.
- Click + Add user/group and select which users or groups you want to have access to uStudio.
- Now you may proceed to admin onboarding as documented here: https://ustudio.zendesk.com/hc/en-us/articles/360052700771