# SAML SSO

Note that SAML SSO is only available to customers on the Business Plan and Enterprise Plan.

## Quick overview

1. Upgrade to Business Plan or higher ([how-to](/plans))
2. Turn on SSO in Eraser ([how-to](https://docs.eraser.io/docs/sso#how-to-enable-sso-in-eraser))
3. Using MS Entra
   1. Install Eraser on your identity provider (e.g. Active Directory) ([how-to](https://docs.eraser.io/docs/sso#how-to-install-eraser-on-azure-entra-active-directory))
   2. Fill out SSO configuration fields in Eraser  (e.g. Active Directory) ([how-to](https://docs.eraser.io/docs/sso#how-to-fill-out-sso-configuration-fields-in-eraser))
   3. Add users to Eraser on your identity provider (e.g. Active Directory) ([how-to](https://docs.eraser.io/docs/sso#how-to-add-users-on-microsoft-entra))
4. Using Okta
   1. Install Eraser on your identity provider (e.g. Okta) ([how-to](https://docs.eraser.io/docs/sso#how-to-install-eraser-on-okta))
   2. Fill out SSO configuration fields in Eraser  (e.g. Okta) ([how-to](https://docs.eraser.io/docs/sso#how-to-enable-sso-in-eraser-from-okta))
   3. Add users to Eraser on your identity provider (e.g. Okta) ([how-to](https://docs.eraser.io/docs/sso#how-to-add-users-on-okta))
5. Send invites to users to join team in Eraser ([how-to](https://docs.eraser.io/docs/sso#how-to-send-a-team-invite-in-eraser))
6. Enable just-in-time (JIT) provisioning

## How to enable SSO in Eraser

Under Settings > [Team Settings](https://app.eraser.io/dashboard/all?settings=team-settings), find the SAML SSO toggle and turn it on. Note that this toggle will only be available if you're on a Business Plan or Enterprise Plan.

Verified Domain and Entity ID should already be filled out.

<Figure src="/assets/d7aa6ac-image.png" alt="" />

## How to install Eraser on MS Entra (AD)

## Configuring Entra

<Callout kind="warning" title="Required role">
An **Entra admin** needs to perform the below
</Callout>

1. On your Entra dashboard, click on "Add > Enterprise application"

<Figure src="/assets/d4d9258-image.png" alt="" />

2. Click on "Create your own application"

<Figure src="/assets/d2785cd-image.png" alt="" />

3. Enter "Eraser" as name of app, select "Integrate any other application you don't find in the gallery (Non-gallery)", and select "Create".

<Figure src="/assets/8679980-image.png" alt="" width="450px" border />

4. In the "Eraser" application profile, select "Set up single sign on"

<Figure src="/assets/71afe66-image.png" alt="" />

5. Select "SAML" as single sign-on method

<Figure src="/assets/9e1907c-image.png" alt="" />

6. In the "Basic SAML Configuration" section, click on "Edit"

<Figure src="/assets/3af9170-image.png" alt="" width="550px" border />

7. Fill in "Identifier (Entity ID)" and "Reply URL (Assertion Consumer Service URL)" with the below information, then click "Save".

* **Identifier (Entity ID):[https://app.eraser.io](https://app.eraser.io)**
* **Reply URL (Assertion Consumer Service URL):[https://app.eraser.io/auth/callback/YOUR-DOMAIN.COM](https://app.eraser.io/auth/callback/YOUR-DOMAIN.COM)**
  * Replace YOUR-DOMAIN.COM with your actual domain. For example, if your domain is acme.com, it would be [https://app.eraser.io/auth/callback/acme.com](https://app.eraser.io/auth/callback/acme.com)
* If you are a single-tenant customer, replace _**app.eraser.io**_ with _**your-subdomain.eraser.io**_

<Figure src="/assets/81a4d75-image.png" alt="" width="550px" border />

8. Make sure SAML assertion encryption is not being applied.
   1. Open "Enterprise Applications > Eraser > Security > Token Encryption"
   2. If there are any active certificates, click on the three dots and click "Deactivate token encryption certificate"

## How to fill out SSO configuration fields in Eraser

<Callout kind="warning" title="Required role">
An **Eraser admin** needs to perform the below
</Callout>

_Note that the below steps are based on Microsoft Entra but any other identity provider (e.g. Okta) can be used as well._

1. Copy "**Login URL**" from the SSO setup page in Entra and paste it into in the "**SAML Sign-In URL**" field in the Eraser [SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings).

<Figure src="/assets/66b4ae8-image.png" alt="" width="600px" border />

<Figure src="/assets/73ab29c-image.png" alt="" />

2. Copy "**Microsoft Entra Identifier**" from the SSO setup page in Entra and paste it into in the "**Identity Provider Issuer**" field in the [Eraser SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings).
   1. Refer to screenshots in the previous step
3. Download "**Certificate (Base 64)**" from the SSO setup page in Entra. Open the downloaded `Eraser.cer` file in a text editor and copy the text content of the file.

<Figure src="/assets/400ed12-image.png" alt="" width="600px" border />

4. Paste the certificate content copied from the previous step into the "**Key x509 Certificate**" field in the [Eraser SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings).

<Figure src="/assets/031f960-image.png" alt="" />

5. Press "Save".

## How to add users on Microsoft Entra

<Callout kind="warning" title="Required role">
An **Entra admin** needs to perform the below
</Callout>

_Note that in order to grant a user access to Eraser, the user must be BOTH granted access to Eraser on Microsoft Entra AND sent a team invite in Eraser._

1. Open the "Eraser" application profile in Microsoft Entra and click on "Assign users and groups"

<Figure src="/assets/4863036-image.png" alt="" />

2. Click on "Add user/group"

<Figure src="/assets/e24e5be-image.png" alt="" />

3. Add users as necessary. Once completed, the added users should show on the screen from the previous step.

## How to install Eraser on Okta

## Configuring Okta

<Callout kind="warning" title="Required role">
An **Okta admin** needs to perform the below
</Callout>

1. On your Okta dashboard, click on "Applications"
2. Click on "Create App Integration"

<Figure src="/assets/a87faff-JGhZlpBRBdOjQYKe2Oipn.png" alt="Screenshot 2024-08-09 at 11.17.31 AM.png" />

3. Select "SAML 2.0" and click "Next"

<Figure src="/assets/e49b8de-J2wtNtAkK_fKoiuUIsyi9.png" alt="Screenshot 2024-08-09 at 11.19.27 AM.png" />

4. Enter "Eraser" as the App Name
5. [Download this file](https://drive.google.com/file/d/1hTOMeSR8hxNdNsBisG3MLJjX5NGerGXJ/view?usp=sharing) to use as the logo. Upload the logo in Okta and click "Next"

<Figure src="/assets/08e9b4d-oOBcQK2N-BZT25E17qrte.png" alt="Screenshot 2024-08-09 at 11.20.56 AM.png" />

6. Fill in "Single sign-on URL" and "Audience URI (SP Entity ID)" with the below information
   1. **Single sign-on URL:**[﻿https://app.eraser.io/auth/callback/YOUR-DOMAIN.COM](https://app.eraser.io/auth/callback/YOUR-DOMAIN.COM)
      1. Replace YOUR-DOMAIN.COM with your actual domain. For example, if your domain is acme.com, it would be [﻿https://app.eraser.io/auth/callback/acme.com](https://app.eraser.io/auth/callback/acme.com)
   2. **Audience URI (SP Entity ID)**:[﻿https://app.eraser.io](https://app.eraser.io/)
7. Make sure the following fields are correct:
   1. "Name ID format" is set to "Unspecified"
   2. "Application username" is set to "Okta username"
   3. Update application username on" is set to "Create and update"

<Figure src="/assets/1cf0ac4-KGHIjuCiGzWiBCiC_q_Ck.png" alt="Screenshot 2024-08-09 at 12.52.23 PM.png" />

8. Add the following **Attribute Statements**:

   1. `FirstName`: `user.firstName`
   2. `LastName`: `user.lastName`

<Figure src="/assets/41ae5f1f0268951f8d7d07065003b1781597e7cdce8a1431bbc109410fce133d-image.png" alt="" width="500px" />

<br />

9. Scroll down and click "Next", you'll see a questionnaire for Okta answering it is optional. Click "Finish" for the next step

<Figure src="/assets/5322811-DA8fkP3BaU_cve7Q_hp9g.png" alt="Screenshot 2024-08-09 at 12.54.59 PM.png" />

10. Scroll down and click on "**More Details**"

<Figure src="/assets/d851e1f-p-dLPjw28RPyrM4GKTZ-Z.png" alt="Screenshot 2024-08-09 at 11.35.08 AM.png" />

<br />

## How to enable SSO in Eraser for Okta

<Callout kind="warning" title="Required role">
An Okta admin needs to perform the below
</Callout>

1. In Eraser Under Settings > [﻿Team Settings](https://app.eraser.io/dashboard/all?settings=team-settings) , find the SAML SSO toggle and turn it on. Note that this toggle will only be available if you're on a Business Plan or Enterprise Plan.Verified Domain and Entity ID should already be filled out.

   <Figure src="/assets/15e4a44-Screenshot_2024-08-12_at_12.51.09_PM.png" alt="" />
2. Copy "**Sign on URL**" from the Sign on page in Okta and paste it into in the "**SAML Sign-In URL**" field in the Eraser [﻿SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings) .
3. Copy "**Issuer**" from the Sign on page in Okta and paste it into in the "**Identity Provider Issuer**" field in the [﻿Eraser SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings) .

<Figure src="/assets/e3826c8-Screenshot_2024-08-12_at_12.45.31_PM.png" alt="" width="450px" />

4. Download the Signing Certificate. Click the download button. Open the downloaded file in a text editor and copy the text content of the file.
5. Paste the certificate content copied from the previous step into the "**Key x509 Certificate**" field in the [﻿Eraser SAML SSO settings page](https://app.eraser.io/dashboard/all?settings=team-settings) .

   <Figure src="/assets/9c4b9f7-Screenshot_2024-08-09_at_12.01.13_PM.png" alt="" />
6. Press "save"

## How to add users on Okta

<Callout kind="warning" title="Required role">
An **Okta admin** needs to perform the below
</Callout>

_Note that in order to grant a user access to Eraser, the user must be BOTH granted access to Eraser in Okta AND sent a team invite in Eraser._

1. In Okta click on the "Assignments" tab

   <Figure src="/assets/51b9c34-Screenshot_2024-08-09_at_12.02.33_PM.png" alt="" />
2. Click "Assign" and select "Assign to People"

   <Figure src="/assets/6474910-Screenshot_2024-08-09_at_12.03.51_PM.png" alt="" />
3. Find the individual you'd like to add and click "Assign"

   <Figure src="/assets/cfe8f3c-Screenshot_2024-08-09_at_12.04.02_PM.png" alt="" />
4. Confirm the new individuals username and click "Save and Go Back". You can select more individuals to add or if you are done you can click "Done"

## How to send a team invite in Eraser

<Callout kind="warning" title="Required role">
An **Eraser admin** needs to perform the below
</Callout>

_Note that in order to grant a user access to Eraser, the user must be BOTH granted access to Eraser on your IdP (i.e. Microsoft Entra or Okta) AND sent a team invite in Eraser, unless JIT provisioning is enabled._

1. Open Settings > [Team Members](https://app.eraser.io/dashboard/all?settings=members).

<Figure src="/assets/4c1f453c0dbff8f020ea0022af4ffbfe687780a84e791132d3c3385ca0b01e33-image.png" alt="" />

2. Invite users as necessary.
   1. An invite email will be sent to the user to join the team.
   2. Note that the team will be billed for each team member.

## Just-in-time (JIT) provisioning

<Callout kind="warning" title="Required role">
An **Eraser admin** can to perform the below
</Callout>

_If just-in-time provisioning is enabled, the admin only needs to add the end user in the IdP without having to invite the user in Eraser as well. Once a user is added on the IdP by the admin, a user will be automatically added to the JIT-enabled team when signining up or signining in using SSO._

Here's how to enable just-in-time provisioning:

1. Open Settings > [Team Members](https://app.eraser.io/dashboard/all?settings=members).

<Figure src="/assets/6a4e4f302055c8c1d45659b41e6c2d4575dde11cbbc18c4f4c3a3bbd1251e3df-image.png" alt="" border />

2. Turn on the toggle "Enable just-in-time provisioning"
