SAML/SSO Authentication Overview
SAML/SSO Authentication can be enabled on your Domotz account to let you and your team take advantage of your company’s Identity Provider to access Domotz services.
There are two steps to ensuring your team can use SAML/SSO; 1) you need to configure Domotz with your company’s Identity Provider, and 2) associate your team members to the SAML/SSO services.
Configuring Domotz with your company’s Identity Provider starts from https://portal.domotz.com. Select Account and then SAML/SSO from the sub-menu.

Setting Up SAML/SSO in Domotz Portal
1. Navigate to the "Account" section and select the "SAML/SSO" tab in the top navigation menu.
2. Choose an Identity Provider by selecting one of the options: Okta, Azure, or Jump Cloud.
3. Enter a name for your SAML/SSO configuration in the "Name" field.
4. Click the "Generate" button to generate the URLs required for configuring your Identity Provider.
5. Once the URLs are generated, click "Create" to complete the setup.
After completing the configuration with your company’s Identity Provider, you will be able to set which users of your team must use SAML/SSO to access Domotz services. This can be done from the Team section in the top menu of the Domotz portal.

Team Management Portal Interface
1. The navigation menu at the top allows access to sections: Apps, Team, Optional Packages, Subscriptions, and Add an Agent. The "Team" section is selected.
2. Below the menu, the Team Management section explains the purpose of managing team members for organizational access.
3. "Team Member Capacity" displays a slider showing the current use (5 members) out of the maximum capacity (25 members), with an additional cost indication. A plus (+) button is available to increase team capacity.
4. To add a new team member, select "Create Team Member."
5. The team member list shows details: "Team Member" name, "Contacts" (email), "Collaboration" checkbox, "Agents" count assigned, "2FA" status, and the "Auth Type" with "Manage" button available for configurations.
6. A checkbox labeled "Select All" allows selecting all members for bulk actions.
In order to change the Authentication type of your team members, click on Manage, and then select the desired option.

Managing Team Member Authentication Settings
1. Navigate to the "Team" section in the Domotz portal.
2. In the "Team Management" area, find the button to "+ Create Team Member" if adding a new member.
3. In the pop-up window, under "Manage Team Member," the email of the member is displayed.
4. Choose the "Authentication Type" for the team member. Options include "2FA-Optional," "2FA-Mandatory," and "SAML/SSO." Select the desired option.
5. Click "Save" to apply changes.
6. To remove the team member, select "Remove Team Member."
Below you can find a step by step tutorial to configure each supported Identity Provider.
Microsoft Azure Active Directory
The following steps will guide you through the configuration of Microsoft Azure Active Directory.
Open Microsoft Azure web interface, and select Azure Active Directory.

Azure portal welcome page options.
1. Start an Azure free trial by clicking "Start" to receive $200 credit toward Azure products and services, plus 12 months of popular free services. Click "Learn more" for additional details.
2. Manage Azure Active Directory by selecting "View" to handle access, set smart policies, and enhance security. Click "Learn more" for further information.
3. Access student benefits by clicking "Explore" to get free software, Azure credit, and Azure Dev Tools after verifying your academic status. Click "Learn more" for more information.
Below these options, find Azure services like Create a resource, Azure Active Directory, Azure AD B2C, Subscriptions, Virtual machines, App Services, Storage accounts, SQL databases, and Azure Database for PostgreSQL. Additional services are accessible through "More services".
From the left menu select Enterprise applications.

Azure Active Directory Overview Menu Navigation
1. Begin by accessing the Microsoft Azure portal.
2. Locate the home section titled "Azure Active Directory" linked with "domotz.com".
3. To view general account information, select "Overview".
4. For initial setup instructions, choose "Getting started".
5. Access the "Preview hub" for upcoming features.
6. Use "Diagnose and solve problems" to troubleshoot issues.
7. Under the "Manage" section, you can handle different categories:
- Select "Users" to manage individual accounts.
- Choose "Groups" to organize users into different teams.
- Access "External Identities" for managing user identities outside your organization.
- Use "Roles and administrators" to adjust roles and permissions.
- Choose "Administrative units" for handling organization-specific units.
8. For application management, select "Enterprise applications".
9. Use "Devices" to manage hardware connected to the directory.
10. Access "App registrations" for registering new applications.
Use these options to navigate and manage various elements within Azure Active Directory.
Create a new application selecting New application from the top sub-menu.

Creating a New Application in Azure Active Directory
1. Open the Azure Active Directory and navigate to the "Enterprise applications" section.
2. In the "Manage" section, select "All applications.”
3. Click the "New application" button located at the top center to begin the process of adding a new application.
4. Use the search and filter options if needed to view, filter, and search applications currently in your organization.
Click on Create your own application; a new panel will open on the right. There you can define your application name and select Create to proceed.

Creating a New Application in Azure AD Gallery
1. Navigate to the "Browse Azure AD Gallery" page. Click on "Create your own application" to start the process of adding a new app.
2. In the "Create your own application" section on the right, enter the name of your app in the "What's the name of your app?" input field.
3. Select the appropriate option for what you want to do with your application. Choices include configuring an Application Proxy, registering an app to integrate with Azure AD, or integrating any other application not found in the gallery.
4. Click the "Create" button to finalize the setup of your new application.
Your custom application has been created, but it now requires some additional configuration to provide SSO within Domotz.
Select Users and groups from the left menu and click on Add user/group

Adding a User or Group in Microsoft Azure.
1. In the Microsoft Azure portal, navigate to the "Manage" section and click on "Users and groups."
2. Select "Add user/group" to initiate the process of adding a new user or group to the "Domotz for my company DEMO" enterprise application.
Click now on Users – None Selected and search/add the desired users from the “Users” panel that appears. The emails on Azure Active Directory must match the ones used by you and your team members on Domotz, otherwise they won’t be able to login using the SSO.
Once you have added all the users that require access to Domotz through Azure SSO, click on Assign.

Assigning Users in Azure Active Directory.
1. Click on "None Selected" under the "Users" section.
2. In the "Users" panel on the right, select each user you want to assign.
3. Click the "Select" button at the bottom of the panel.
4. Once the users are selected, click the "Assign" button to complete the process.
Go back to the Overview section.

Manage Users and Groups in Microsoft Azure Application
1. Navigate to the left sidebar and select "Users and groups" under the "Manage" section.
2. Use the "Add user/group" option at the top to include new users or groups.
3. Use "Edit" to modify existing entries or "Remove" to delete them.
4. Access "Update Credentials" to change user passwords or authentication details.
5. Click "Columns" to customize the information displayed in the list.
6. Search for users or groups using the search bar by entering a display name.
7. Ensure the application is set to appear for assigned users within "My Apps." Adjust settings in properties if needed to control user visibility.
Now you are ready to setup Single Sign on.
Select 2. Set up single sign on

Azure Application Overview and Setup Steps
1. On the Azure Application Overview page, note the application properties: Name (Domotz for my company DEMO), Application ID, and Object ID.
2. In the "Getting Started" section, follow these steps:
- Assign users and groups: Access the application for specific users. Use the option to assign users and groups.
- Set up single sign-on: Enable user login with Azure AD credentials. Click "Get started" under this option.
- Provision user accounts: Automatically create and delete user accounts in the application. Select "Get started" for more information.
- Establish conditional access: Secure the application with a custom access policy. Click "Create a policy" to begin.
- Enable self-service: Allow users to request application access using their Azure AD credentials. Click "Get started" to proceed.
Please click on the SAML sign-on method

Enable SAML Single Sign-On in Azure.
1. Navigate to the Azure portal and access the "Enterprise applications" section.
2. Select "Single sign-on" from the Manage menu on the left.
3. Under "Select a single sign-on method," choose "SAML" for rich and secure authentication using the Security Assertion Markup Language protocol.
Now after leaving the SAML window open on another web browser tab, go back to the Domotz portal, and ensure you have selected Azure for your Identity Provider.
Then, name your integration and click on Generate.

Configuring SAML/SSO in Domotz.
1. Navigate to the "SAML/SSO" tab in the Domotz portal.
2. Under "Security Assertion Markup Language / Single Sign On," select your Identity Provider. Options include Okta, Azure, JumpCloud, and Evo Security.
3. Enter a name for the SAML/SSO configuration in the "Name" field. Example: "Active Directory SSO."
4. Click "Generate" to create URLs for configuring your Identity Provider.
5. Finally, click "Create" to complete the configuration process.
Click on Download Metadata file; the download of a .zip file will start. Open the .zip file and extract the XML file contained in it. You will need to upload it on the Azure web interface in a few steps.

SAML/SSO Configuration in Domotz Portal
1. Navigate to the "SAML/SSO" tab in the Domotz Portal.
2. Select your Identity Provider. In this example, "Azure" is chosen.
3. Enter a name for the configuration. The example uses "Active Directory SSO."
4. Review the "SP Entity ID" and "SP Assertion URL" provided; copy them as needed using the copy icon.
5. Download the metadata file by clicking the "Download Metadata file" button. Follow your Identity Provider's instructions to complete the upload.
Go back to the Azure web interface, select Upload metadata file from the top sub-menu, and upload the XML file downloaded from Domotz.

Setting up Single Sign-On in Microsoft Azure for a SAML-based application.
1. In the Azure portal, navigate to "Single sign-on" under the "Manage" section on the left sidebar.
2. Click on "Upload metadata file" at the top of the page.
3. In the "Upload metadata file" dialog, click the icon to browse and select your metadata file.
4. Click the "Add" button to upload the metadata. Required fields like "Identifier" and "Reply URL" will populate automatically.
A set of pre-filled fields will appear, select Save to continue.

Basic SAML Configuration
1. Click the "Save" icon on the top left to save any changes made.
2. In the "Identifier (Entity ID)" field, input or confirm the default identifier URL. This is used as the audience for SAML response in IDP-initiated SSO.
3. In the "Reply URL (Assertion Consumer Service URL)" field, input or confirm the default reply URL. This is used as the destination for the SAML response for IDP-initiated SSO.
4. A notification will confirm a successful SAML file upload, indicating that the "Domotz on Azure AD.xml" file was successfully uploaded.
You will now need to download the Federation Metadata XML file from Azure, and upload it on Domotz.
Click the Download button to save this XML file.

Setup SAML-based Single Sign-on in Microsoft Azure for Domotz.
1. In the left-hand navigation pane, select "Single sign-on" under the "Manage" section.
2. Scroll to the "SAML Signing Certificate" section.
3. Locate and select the "Download" link next to the "Federation Metadata XML" to download the certificate file needed for configuring SAML-based sign-on with Domotz.
Go back to the Domotz portal again, mark the required checkbox as done, and upload the Federation XML file that you have created and downloaded from Azure in the previous step.

Completing SAML/SSO Configuration and Uploading Metadata
1. Ensure the checkbox next to "Have you completed the SAML/SSO configuration on your Identity Provider?" is checked to confirm that SAML/SSO configuration is complete.
2. Click the "Upload metadata file" button to upload the metadata file provided by your Identity Provider.
After these steps, proceed to create or delete the configuration as needed using the respective "Create" or "Delete Configuration" buttons.
Check that the xml file has been uploaded and click on Create.

Configuring SAML/SSO for Domotz.
1. Download the metadata file by clicking the "Download Metadata file" button.
2. Ensure you have completed the SAML/SSO configuration with your Identity Provider.
3. Confirm your configuration by checking the box labeled "Have you completed the SAML/SSO configuration on your Identity Provider?"
4. Upload the metadata file named "Domotz for my company DEMO.xml."
5. After uploading, click the "Create" button to finalize the configuration.
You are now ready to test and activate your SSO application.
Click on Test Configuration to perform a test:

Testing SAML Configuration in Domotz Portal
1. Verify the name of the configuration as “Active Directory SSO.”
2. Review the SAML Single Sign-On setup confirmation, dated 2021 Dec 21.
3. Note the SP Entity ID and SP Assertion URL provided in the fields.
4. Download the metadata file using the “Download Metadata file” button to upload it to your Identity Provider.
5. Click the “Test Configuration” button to ensure the SSO setup works correctly.
6. Confirm that SAML Single Sign-On is enabled, indicated by the toggle switch being on.
7. Use the “Delete Configuration” button if removal of the setup is necessary.
If the test is successful, you will be able to enable SAML/SSO on your account or on your team members’, by clicking on the SAML Single-On enable for this user toggle.

Enabling SAML/SSO Configuration
1. Ensure the toggle for "SAML Single Sign-On enabled for this user" is switched on.
2. In the confirmation dialog, read the message explaining that enabling SAML/SSO will automatically log you out and require SAML/SSO credentials for future logins.
3. Check the box labeled "I've verified the configuration and I want to proceed," then click "Enable SAML/SSO Configuration" to confirm.
Be sure to configure each Team Member for SAML/SSO under the Team section on portal.domotz.com.
Azure IdP-Initiated SSO
If you want to access Domotz from the My Apps page, you have to initiate SSO from the Identity provided-initiated (IDP) SSO.
How to do it:
Step 1: Open the Azure Configuration and write in the Relay State field the following string:
state=https://portal.domotz.com/webapp/#/sso?

Setting Up Single Sign-On (SSO) with SAML
1. Basic SAML Configuration: Enter the 'Identifier (Entity ID)', 'Reply URL (Assertion Consumer Service URL)', and optional 'Sign on URL' in the respective fields. 'Relay State' and 'Logout URL' are also provided for configuration.
2. User Attributes & Claims: Define user attributes such as 'givenname', 'surname', 'emailaddress', and 'Unique User Identifier' with corresponding values from the user information.
3. SAML Signing Certificate: Confirm the 'Status' is 'Active' and check the 'Expiration' date. Download necessary certificates including 'Certificate (Base64)', 'Certificate (Raw)', and 'Federation Metadata XML' for secure setup.
4. Set up Test Domotz SSO: Configure the application by linking it with Azure AD using the 'Login URL', 'Azure AD Identifier', and 'Logout URL'. View step-by-step instructions if needed.
5. Test SSO with Test Domotz SSO: Use the 'Test' button to verify if single sign-on is functioning properly. Ensure users are added to 'Users and groups' before testing.
Step 2: Open My Apps from Microsoft and enter in the Domotz Webapp with a single click:

Managing Applications in Microsoft My Apps Portal
1. Open a web browser and navigate to the Microsoft My Apps portal at myapplications.microsoft.com.
2. Sign in if prompted.
3. At the top-left, ensure "My Apps" is selected to view your available applications.
4. Use the navigation options to switch between the "Examples" or "All Apps" tabs as needed.
5. Locate the specific application you want, such as "Test Domotz SSO," displayed with its icon.
6. Click on the application icon to launch or manage it.
Evo
The following steps will guide you through the configuration of Evo Security.

Setting Up SAML/SSO on Domotz
1. Navigate to the "SAML/SSO" tab in the Domotz portal.
2. Under "Please select your Identity Provider," choose one of the following options: Okta, Azure, JumpCloud, or Evo Security.
3. Enter a name for the SAML/SSO Domotz configuration in the "Name" field.
4. Click the "Generate" button to create the URLs needed for configuring your Identity Provider.
5. Finally, click "Create" to complete the setup process.

Adding a New Tenant in Evo Dashboard
1. Navigate to the "Tenants" section in the Evo dashboard, located in the upper left corner.
2. Click on "Tenants" to open a dropdown menu.
3. Use the "Search" bar to find existing tenants.
4. Select the "+ Add New Tenant" button to initiate adding a new tenant.
5. View tenant names listed below, such as "Domotzdev."
6. Monitor additional dashboard sections for "Keys," showing values like "3" and "4."
7. Review "Authentication Activity" detailing Username, Request, Result, Date, Time, Environment, and IP Address.
8. Click "See All Activity" to view a comprehensive activity log.

Integrations Page Interface.
1. Navigate to the sidebar on the left and select "Integrations" from the menu options.
2. Use the search bar labeled "Search for Integration" to find specific integrations.
3. Available integrations are displayed below, including options like "SAML Web App" for applying MFA, "Office 365" for SAML integration with Office 365, and "Windows Desktop" for downloading the MSI package for Windows Desktop.
4. Top navigation includes dropdowns for "Professional Settings" and user account management under "Alessandro Paglario".

Integrating Services in Evo Software Interface
1. Navigate to the Evo dashboard. On the left sidebar, select "Integrations" to view available integration options.
2. Browse through the integration options displayed as tiles.
3. To set up a new cloud Radius server, select the "Radius Server" tile.
4. For connecting Evo with Liongard to enable Single Sign-On (SSO), choose the "Liongard" tile.
5. To enable SSO with Domotz, click the "Domotz SAML" tile.
6. Additional integration options include ITGlue, Auvik, and Dropbox. Select the desired service to proceed with integration setup.

Integrating Evo with Domotz using SAML
1. In the Evo interface, select "Integrations" from the left-hand menu.
2. Under "Domotz SAML," note the instructions for connecting Evo to Domotz.
3. Download the metadata file in .xml format using the download button provided.
4. Log in to the Domotz admin portal.
5. Navigate to the SAML/SSO section and upload the downloaded metadata file.
6. Click "Test Connection" to verify the integration.
7. Ensure the Evo Secure Login mobile app is installed and QR codes in the Evo portal are scanned for authentication.
8. Save the integration in Domotz once testing is complete.
Download the Metadata File, you’ll need it to complete the configuration on the Domotz side.
Leave this window open and go back to the Domotz portal. After selecting Evo Security, name your integration and click on Generate.
An SP Entity ID and SP Assertion Url parameter will be generated.

Configuring SAML/SSO in Domotz Portal
1. Select your identity provider from the options: Okta, Azure, JumpCloud, or Evo Security. The Evo Security option is selected.
2. Enter a name for the SAML/SSO configuration in the "Name" field, labeled as "Evo Security SAML."
3. Fill in the "SP Entity ID" and "SP Assertion Url" fields with the provided values.
4. Check the box to confirm the completion of SAML/SSO configuration on your Identity Provider.
5. To upload metadata, click the "Upload metadata file" button if applicable.
6. Click "Create" to save the configuration or "Delete Configuration" to remove it.
Select the checkbox “Have you completed the SAML/SSO configuration on your Identity Provider?” and then upload the metadata file you previously saved by clicking on the “Upload Metadata File” button.

Configuring SAML/SSO in Domotz Portal
1. Navigate to the "SAML/SSO" tab under the "Account" section.
2. Select an Identity Provider from options such as Okta, Azure, JumpCloud, or Evo Security. Enable "Evo Security" for this setup.
3. Enter a name for the configuration in the "Name" field, e.g., "Evo Security SAML."
4. Review the "SP Entity ID" field, which shows the configured Entity ID.
5. Enter the "SP Assertion Url" as provided by your Identity Provider, e.g., "https://api-testing-eu-central-1-cell-1.domotz.nl/sso."
6. Click "Test Configuration" to verify the settings.
7. Ensure the "SAML Single Sign-On" toggle is enabled for SSO functionality.
8. Use the "Delete Configuration" button if you need to remove this setup.
You are now ready to test and activate your SSO application.
Click on Test Configuration to perform a test.
If all the steps have been followed you will see a successful message. You can now enable SAML/SSO on your account or on your team members.
Be sure to configure each Team Member for SAML/SSO under the Team section of portal.domotz.com.
Okta
The following steps will guide you through the configuration of Okta.

Setting Up SAML/SSO in Domotz Portal
1. Navigate to the "Account" section and select the "SAML/SSO" tab in the top navigation menu.
2. Choose an Identity Provider by selecting one of the options: Okta, Azure, or Jump Cloud.
3. Enter a name for your SAML/SSO configuration in the "Name" field.
4. Click the "Generate" button to generate the URLs required for configuring your Identity Provider.
5. Once the URLs are generated, click "Create" to complete the setup.
Open the Okta web interface, and select Applications from the top menu.

Navigating to the Applications Section in Okta
1. In the top navigation bar, locate and click on “Applications.”
2. A dropdown menu will appear with options.
3. Select “Applications” to view or manage applications.
4. Choose “Self Service” if you need to access self-service options related to applications.
Click on Add Application.

Okta Applications Page Navigation
1. Navigate to the "Applications" tab located in the top menu bar between "Directory" and "Security."
2. Click on "Add Application" to begin the process of adding a new application.
3. Use the "Assign Applications" button to assign existing applications to users or groups.
4. Use the search bar to locate specific applications quickly.
5. The "Status" panel shows the number of applications that are currently active.
Select SAML 2.0 option and click on Create.

Add a New Application in the Dashboard
1. To return to the main applications list, click on "Back to Applications."
2. To start adding a new application, select "Create New App" located on the right side of the screen.

Creating a New Application Integration
1. Under "Platform," select "Web" from the dropdown menu.
2. Choose a "Sign on method":
- Select "SAML 2.0" to use the SAML protocol for logging users into the app.
- Alternatively, choose "OpenID Connect" to use the OpenID Connect protocol for logging users into an app you’ve built.
3. Click the "Create" button to proceed, or "Cancel" to exit.
Define your application name and select Next to proceed.

Creating a SAML Integration - General Settings
1. Enter the app name in the "App name" field, e.g., "Domotz Integration."
2. Optionally, add an app logo by clicking "Browse," selecting an image, and clicking "Upload Logo." Ensure the image is PNG, JPG, or GIF and less than 1MB. For optimal results, use a PNG image that is at least 420x120 pixels, landscape-oriented, and has a transparent background.
3. In the "App visibility" section, check the boxes if you do not want the application icon displayed to users or in the Okta Mobile app.
4. Click "Next" to continue to the next step.
5. Click "Cancel" to discard changes and exit the configuration.
To proceed with configuring Okta, you need to obtain the required configuration parameters from the Domotz side.
Leave this window open and go back to the Domotz portal. After selecting Okta, name your integration and click on Generate.

Setting Up SAML/SSO in Domotz
1. Navigate to the "SAML/SSO" tab in the settings menu.
2. Choose your Identity Provider. Options include Okta, Azure, and Jump Cloud. Select "Okta" as the provider.
3. Enter a name for the configuration in the "Name" field, such as "Okta SSO."
4. Click on the "Generate" button to create the URLs needed to configure your Identity Provider.
5. Once generated, click "Create" to complete the setup process.
An SP Entity ID and SP Assertion Url parameter will be generated. You will need to copy and paste them during the following step on the Okta web interface.

Steps to configure SAML/SSO in the Domotz web interface.
1. Navigate to the "SAML/SSO" tab in the interface menu.
2. Choose your Identity Provider by selecting one of the radio buttons: "Okta," "Azure," or "Jump Cloud." Ensure "Okta" is selected for this setup.
3. Enter a name for your configuration in the "Name" field, such as "Okta SSO."
4. Review the "SP Entity ID" field, which contains a blurred section, and ensure it matches your service provider details.
5. Verify the "SP Assertion Url," which displays the URL for API testing.
6. Confirm completion of the SAML/SSO configuration on your Identity Provider by checking the corresponding box.
7. Upload the metadata file by selecting "Upload metadata file."
8. To finalize the setup, click "Create." If needed, you can remove the configuration by clicking "Delete Configuration."
Go back to the Okta web interface that was left open, and paste the SP Entity ID copied from Domotz into the Audience URI (SP Entity ID), and the SP Assertion Url into the Single sign on URL.
Additionally, set an attribute with Name “domotz”, and with Value “1”. Please note: without this step the SSO integration will not work on Domotz.
When completed, select Next to proceed.

SAML Settings Configuration
1. Fill in the "Single sign on URL" with the given URL and check the box to use this for Recipient URL and Destination URL. Optionally, allow the use of other SSO URLs.
2. Enter an "Audience URI (SP Entity ID)" and specify a "Default RelayState" if needed.
3. Set the "Name ID format" to "Unspecified" or select another option. Choose the "Application username" format, such as "Okta username."
4. Add a "Name" under the section for attribute statements, choose a "Name format," and enter a "Value." Click "Add Another" to include more attributes as needed.
5. In the "Group Attribute Statements" section, optionally add a "Name," choose a "Name format," and set a "Filter" condition.
6. Click "Preview the SAML Assertion" to see the XML data generated, which helps verify the entered information.
7. Use the "Previous" and "Cancel" buttons to navigate or abort changes, or select "Next" to proceed.
Select the option I’m an Okta customer adding an internal app and click on Finish.

Edit SAML Integration Feedback Step
1. Navigate to the "Edit SAML Integration" section.
2. In the process flow, confirm you are on the third step titled "Feedback."
3. Select your role under "Are you a customer or partner?" Choose between:
- "I'm an Okta customer adding an internal app."
- "I'm a software vendor. I'd like to integrate my app with Okta."
4. On the right, note the explanation titled "Why are you asking me this?" which explains the purpose of the form in providing Okta Support with background information.
Right-click on Identity Provider metadata link, and Save Link As…; save the file with XML extension in the name (e.g. metadata.xml).

Domotz Integration Sign On Methods Configuration
1. Access the "Domotz Integration" page by navigating to the Applications section, ensuring it is set to "Active" for use.
2. Open the "Sign On" tab to manage sign-on methods for the application.
3. Review the "Settings" section detailing "Sign On Methods." Note that some methods require additional setup in third-party applications.
4. Under "SAML 2.0," check that it is selected as the default sign-on option.
5. For initial setup, click "View Setup Instructions" to complete the necessary configuration.
6. To save identity provider metadata, right-click on the link and select "Save Link As…" in the context menu.
Go back to the Domotz portal, mark the required checkbox as done, and upload the metadata XML file that you downloaded during the previous step.

SAML/SSO Configuration Setup in Domotz
1. Navigate to the "SAML/SSO" tab in the Domotz settings.
2. Select your Identity Provider by choosing one of the options: Okta, Azure, or Jump Cloud. In the example, "Okta" is selected.
3. Enter a name for your SAML/SSO configuration in the "Name" field. For instance, type "Okta SSO."
4. Review the "SP Entity ID" and "SP Assertion URL" fields, which should display the relevant URLs for your configuration.
5. Confirm that the SAML/SSO configuration has been completed on your Identity Provider by checking the corresponding box.
6. Upload the metadata file provided by your Identity Provider using the "Upload metadata file" button.
7. Finalize the setup by clicking "Create" to configure the settings. Use "Delete Configuration" if you need to remove it.
Click on Create.

Configuring SAML/SSO in Domotz
1. Navigate to the "SAML/SSO" tab in Domotz.
2. Select your Identity Provider by choosing one of the radio buttons: Okta, Azure, or Jump Cloud.
3. Under "Name," enter a name for the SAML/SSO configuration, such as "Okta SSO."
4. Note the SP Entity ID and SP Assertion URL provided for your setup.
5. Confirm that you have completed the SAML/SSO configuration on your Identity Provider.
6. If needed, upload metadata using the "Upload Metadata" section.
7. Use the "Create" button to finalize the configuration or "Delete Configuration" if necessary.
Your SSO application is now configured to communicate with Domotz, but in order for it to work with your Domotz user and your team, you will need to select which Okta accounts can use the SSO application.
Go back to Okta web interface and select Assignments from your application sub-menu. Then click on Assign, Assign to People.

Assigning Users or Groups in Domotz Integration.
1. Navigate to the "Assignments" tab within the Domotz Integration section.
2. Click the "Assign" button to open options.
3. Select "Assign to People" to assign tasks to individual users, or "Assign to Groups" to assign tasks to groups.
4. Use the search bar on the right to filter and find specific users or groups.
5. The main panel displays assignment details, but currently shows "No users found."
Search and add the desired users. The emails on Okta must match the ones used by you and your team members on Domotz, otherwise they won’t be able to login using SSO.
Once you have added all the users that must be able to use your Okta SSO application, you have completed the configuration of your Okta application.

Managing Assignments in Domotz Integration
1. Navigate to the "Assignments" tab within the Domotz Integration settings.
2. To assign resources, use the "Assign" button located above the list of users.
3. To convert existing assignments, select "Convert Assignments."
4. Filter the view by selecting "People" or "Groups" on the left side panel under "FILTERS."
5. The main pane displays a list of people with their email addresses and types (e.g., Individual).
6. Use the search bar to find specific users or filter by selecting the dropdown to view people only.
7. Edit or remove user assignments using the pencil (edit) or X (remove) icons next to each user's name.
You are now ready to test and activate your SSO application on Domotz. Go back to Domotz portal and click on Test Configuration.

Configure SAML/SSO on Domotz.
1. Navigate to the "SAML/SSO" tab on the top menu.
2. Select your Identity Provider by choosing "Okta" from the options available.
3. Enter a name for the configuration in the "Name" field, such as "Okta SSO".
4. Review the details below, noting that the SAML Single Sign-On was configured on November 13, 2020.
5. Ensure your "SP Entity ID" and "SP Assertion URL" are correctly entered. The URL shown is: "https://api-testing-eu-central-1-cell-1.domotz.nl/...".
6. Use the "Test Configuration" button to verify the setup.
7. Enable SAML Single Sign-On for the user with the toggle switch, if needed.
8. To remove the configuration, use the "Delete Configuration" button.
If all the steps have been followed you will see a successful message. You can now enable SAML/SSO on your account or on your team members. Be sure to configure each Team Member for SAML/SSO under the Team section of portal.domotz.com.

Authentication Confirmation Screen
1. A confirmation message states that the user "dev@domotz.com" has been successfully authenticated.
2. The "Principal Data" section presents a table with four key data points:
- "Principal (Domotz user name)" shows "dev@domotz.com".
- "Successfully authenticated" indicates "True".
- "NameID" displays as "dev@domotz.com".
- "Principal extracted from attribute" lists "NameID".
These details confirm successful authentication and provide information about the user identity and authentication status.
Okta IdP-Initiated SSO
In the SAML configuration on Okta, set the Default RelayState field to:
state=https://portal.domotz.com/webapp/#/sso?
and save the configuration.

Editing SAML Integration Settings
1. Navigate to the "Configure SAML" tab.
2. Under "SAML Settings," locate "Single sign on URL," and ensure it is set to `https://api-testing-eu-central-1-cell-1.domotz.nl/saml-ap`. Check the box for "Use this for Recipient URL and Destination URL."
3. Set the "Audience URI (SP Entity ID)" to `https://api-testing-eu-central-1-cell-1.domotz.nl/saml-ap`.
4. In the "Default RelayState" field, enter `state=https://portal.domotz.com/webapp/#/sso?`. If left blank, a default RelayState is sent.
5. Leave "Name ID format" as "Unspecified."
6. Set "Application username" to "Okta username."
7. For "Update application username on," choose "Create and update."
The form generates XML for the app's SAML request. Refer to the app's documentation for details on required information.
After that, you will be able to login on Domotz from your My Apps section in Okta:

Accessing a Work Application in Okta
1. On the Okta dashboard, navigate to the "My Apps" section.
2. Locate the "Work" category under "My Apps."
3. Find the "Domotz Login" application within the "Work" category.
4. To launch the application, click the "Launch App" button on the right panel under "Domotz Login."
JumpCloud
The following steps will guide you through the configuration of JumpCloud.

SAML/SSO Identity Provider Configuration
1. Navigate to the "SAML/SSO" tab under "Account" settings.
2. Select your Identity Provider by choosing one of the radio buttons: Okta, Azure, or Jump Cloud.
3. Enter a name for your SAML/SSO Domotz configuration in the "Name" field.
4. Click "Generate" to create the URIs necessary for configuring your Identity Provider.
5. Once the URIs are generated, click "Create" to finalize the configuration setup.
In order to proceed with the JumpCloud configuration you need to obtain the required configuration parameters from Domotz.
After selecting JumpCloud, name your integration and click on Generate.

Setting Up SAML/SSO in the Domotz Portal
1. Navigate to the "Account" section and open the "SAML/SSO" tab.
2. Choose your Identity Provider by selecting one of the available options: Okta, Azure, or JumpCloud. Ensure JumpCloud is selected for this setup.
3. Enter your desired configuration name in the "Name" field provided below.
4. Click the "Generate" button to create the necessary URIs for configuring your Identity Provider.
5. Once the URIs are generated, click "Create" to complete the configuration process.
Click on Download Metadata file; the download of a .zip file will start. Open the .zip file and extract the XML file contained in it. You will need to upload it on the JumpCloud web interface in a few steps.

Setting Up SAML/SSO in Domotz
1. Navigate to the "SAML/SSO" tab in the Domotz portal.
2. Select your identity provider from the options: Okta, Azure, or JumpCloud. Choose JumpCloud in this example.
3. Enter a name for your SAML/SSO configuration in the "Name" field. Example: "JumpCloud SSO."
4. Note the "SP Entity ID" field; it is pre-filled.
5. Review the "SP Assertion Url" field, which contains a URL.
6. Click "Download Metadata file" to obtain the necessary file to upload to your identity provider.
7. Confirm completion by checking "Have you completed the SAML/SSO configuration on your Identity Provider?"
8. Use "Upload Metadata file" to upload the file provided by your identity provider.
9. Once ready, click "Create" to finalize the configuration or "Delete Configuration" to remove it.
Open the JumpCloud web interface, and select SSO from the left menu. Create a new application selecting the “+”button at the top of the page.

How to Add Your First SSO Application in JumpCloud
1. Navigate to the "SSO" section in the JumpCloud admin panel. Find it under "USER AUTHENTICATION" on the left sidebar.
2. Click the green plus (+) button in the top left area to view a list of pre-built SSO connectors.
3. Follow the on-screen instructions to control user access to web apps via SAML 2.0. For more guidance, use the "Learn how" link provided.
4. Notice the options to export metadata and delete applications, located on the top right side of the SSO panel.
Use these steps to efficiently set up and manage your SSO applications.
Click on Custom SAML App at the bottom.

Configure a New SSO Application in JumpCloud.
1. Navigate to the "SSO" section under "User Authentication" in the left sidebar menu.
2. Select "Configure New SSO Application" from the main panel.
3. Use the search bar to find the desired application from a list of available options.
4. Click "configure" beside the selected application to start setup. Available applications like 10,000ft, 15Five, 4me, 7Geese, and 8x8 are listed, each offering different functionalities such as JIT Provisioning.
5. If the application isn’t listed, select either "Custom SAML App" or "URL Bookmark" to set up a custom configuration.
Define your application name in the General Info section.

Configuring New Application Details for SSO
1. In the "Details" tab under "New Application," locate the "General Info" section.
2. Enter the display label as "Domotz SSO" in the designated field.
3. Optionally, provide a description to share specific application information visible in the User Portal.
4. Under "Display Option," select either "Logo" or "Color Indicator" for identification.
5. If "Color Indicator" is chosen, pick a color from the available options below to represent the application.
Scroll down to the Single Sign-On Configuration section, and click on Upload Metadata. Now, upload the Domotz metadata file you have downloaded from Domotz. Some fields will be automatically filled.

Configuring Single Sign-On for a New Application
1. Navigate to the "SSO" section and select "New Application" on the left sidebar.
2. Under the "Details" tab, locate the "Single Sign-On Configuration" section.
3. Click "Upload Metadata" to add your service provider metadata.
4. Fill in the "IdP Entity ID" field with your Identity Provider's entity ID.
5. Enter the "SP Entity ID" in the corresponding field for your Service Provider's entity ID.
6. Provide the "ACS URL" in the designated field, starting with "https://".
Additional configuration details can be found in the linked Knowledge Base article.
Type in the IdP Entity ID, which is a unique identifier for the integration with Domotz (e.g. com.domotz.yourcompanyname).

Single Sign-On Configuration for a New Application
1. In the Single Sign-On Configuration section, click "Upload Metadata" under Service Provider Metadata to upload the necessary metadata file.
2. Enter your IdP Entity ID as "com.domotz.yourcompanyname" in the provided field.
3. Input the SP Entity ID in the designated text box.
4. Specify the ACS URL by entering the URL in the appropriate field.
5. To upload the SP Certificate, click "Upload SP Certificate."
6. Set the SAMLSubject NameID to "email" by selecting it from the dropdown menu.
7. The SAMLSubject NameID Format should be set to "urn:oasis:names:tc:SAML:2.0:nameid-format:persistent."
Ensure all fields are correctly filled to configure Single Sign-On successfully.
Select the Declare Redirect Endpoint checkbox, and then click on Activate at the bottom of the form.

Configuring a New SSO Application
1. Enter the SP Entity ID in the provided field.
2. Fill in the ACS URL, such as the example URL shown.
3. Click "Upload SP Certificate" to upload the needed certificate.
4. Set the SAML Subject NameID to "email."
5. Choose the appropriate SAML Subject NameID Format from the dropdown.
6. Select the Signature Algorithm, for example, "RSA-SHA256."
7. Check the box for "Sign Assertion" if needed.
8. Specify the Default RelayState if applicable.
9. Provide the Login URL in the designated field.
10. Ensure "Declare Redirect Endpoint" is checked.
11. Review the IDP URL provided for correct configuration before activation.
The JumpCloud application has now been created. Now you will need to export the configuration into Domotz. Select the application you just created from the list.

Managing Applications in JumpCloud
1. Navigate to the "Applications" section from the left-side menu under "USER MANAGEMENT."
2. In the "Applications" panel, you can see a list of applications. Use the search bar at the top to find specific applications by name.
3. View the application details such as "Status," "Name," "Display Label," "Supported Functionality," and "IdP URL."
4. To manage an application, select the checkboxes next to the application names. Options to "export metadata" or "delete" are available at the top.
5. The "Domotz SSO" application is currently listed, with its IdP URL provided for SSO configuration purposes.
Scroll down to Single Sign-On Configuration section, and click on Export Metadata button. This will start the download of the JumpCloud metadata file.

Single Sign-On (SSO) Configuration in SAML 2.0 Interface
1. Navigate to the "SSO" section of the application, specifically under "Details."
2. Review the "SAML 2.0" section to check the status of the IDP Certificate validity, which expires on 11-13-2025, and view the IDP Private Key and Single Sign-On activation status.
3. Under "Single Sign-On Configuration," you can export metadata by clicking the "Export Metadata" button under the JumpCloud Metadata section.
4. To upload service provider metadata, select the "Upload Metadata" button in the Service Provider Metadata section.
5. Ensure your IdP Entity ID is correctly entered in the provided field, such as "com.domotz.yourcompanyname."
Go back to the Domotz portal, mark the required checkbox as done, and upload the metadata XML file that you have downloaded during the previous step.

Configuring SAML/SSO on Domotz
1. Select your Identity Provider by choosing between Okta, Azure, or JumpCloud. Here, JumpCloud is selected.
2. Enter a name for your SAML/SSO configuration in the "Name" field. The example name is "JumpCloud SSO."
3. Copy the provided "SP Entity ID" and "SP Assertion URL" for your records.
4. Click the "Download Metadata file" button to save the metadata file generated by Domotz.
5. Confirm you have completed the SAML/SSO configuration on your Identity Provider by selecting the checkbox.
6. Upload the Identity Provider's metadata file using the "Upload metadata file" button.
7. Once ready, click "Create" to finalize the configuration. Use "Delete Configuration" if needed to remove it.
Click on Create.

Setting Up SAML/SSO Configuration in Domotz
1. Select your Identity Provider. Choose from options including Okta, Azure, or JumpCloud. JumpCloud is selected in this example.
2. Enter a name for the configuration. "JumpCloud SSO" is provided as an example.
3. Identify the SP Entity ID and SP Assertion URL. These are specific to your configuration.
4. Download the metadata file needed for your Identity Provider by clicking "Download Metadata file."
5. Confirm completion of the SAML/SSO configuration with your Identity Provider by checking the provided checkbox.
6. Upload the metadata file if required. The uploaded file is named "JumpCloud.xml."
7. Click "Create" to finalize the configuration. Use "Delete Configuration" to remove it if necessary.
Your SSO application is now configured to communicate with Domotz, but in order for it to work with your Domotz username and your team, you will need to select which JumpCloud accounts can use the SSO application.
Go back to the JumpCloud web interface and select User Groups within your application. Select the User Groups that must have access to the SSO application using the left checkboxes. When finished click on Save.
You can configure JumpCloud User Groups from the left menu.
The emails on JumpCloud must match the ones used by you or your team members on Domotz, otherwise they won’t be able to login using the JumpCloud SSO.

Configuring User Groups for SAML 2.0 in SSO Settings
1. Navigate to the "User Groups" tab within the SSO settings under SAML 2.0.
2. Check the information about IDP Certificate Validity, IDP Private Key Validity, and Single Sign-On activation on the left panel.
3. In the "User Groups" section, a search box is available to filter groups.
4. The display indicates "1 of 1 user groups bound" to show the current group configurations.
5. Check the box labeled "show bound user group" to view details.
6. Under "Type," there is a checkbox to include user groups, currently showing "All Users."
7. Select "save" to apply any changes, or select "cancel" to discard changes.
You are now ready to test and activate your SSO application on Domotz. Go back to the Domotz portal and click on Test Configuration.

Domotz SAML/SSO Configuration Steps
1. In the Domotz portal, navigate to the "SAML/SSO" tab under the settings menu.
2. Select your Identity Provider. Choose "JumpCloud" from the options.
3. Enter a name for the configuration in the "Name" field. Example: "JumpCloud SSO".
4. Note the "SP Entity ID" field, which contains a unique identifier for the service provider.
5. Review the "SP Assertion Url" field, which shows the service provider's assertion URL.
6. Download the metadata file by clicking "Download Metadata file" to upload to your Identity Provider.
7. Click on "Test Configuration" to ensure that the setup is correct.
8. Ensure "SAML Single Sign-On enabled for this user" is toggled on.
9. Use "Delete Configuration" if you need to remove this setup.
If all the steps have been followed you will see a successful message. You can now enable SAML/SSO on your account or for your team members. Be sure to configure each Team Member for SAML/SSO under the Team section of portal.domotz.com.

Authentication Confirmation Screen
1. A confirmation message states that the user "dev@domotz.com" has been successfully authenticated.
2. The "Principal Data" section presents a table with four key data points:
- "Principal (Domotz user name)" shows "dev@domotz.com".
- "Successfully authenticated" indicates "True".
- "NameID" displays as "dev@domotz.com".
- "Principal extracted from attribute" lists "NameID".
These details confirm successful authentication and provide information about the user identity and authentication status.
JumpCloud IdP-Initiated SSO
Open your application General Info section

SAML 2.0 Single Sign-On Configuration
1. In the Single Sign-On (SSO) settings, select the "Details" tab.
2. Click on "General Info" to expand the section.
3. Under "Single Sign-On Configuration," there are options for managing metadata:
- Click "Export Metadata" to download JumpCloud Metadata.
- Click "Upload Metadata" to import Service Provider Metadata.
4. In the "IdP Entity ID" field, ensure the value is set correctly, e.g., "com.domotz.yourcompanyname".
Set the following URL set in the “Default RelayState” field: https://portal.domotz.com/webapp/#/sso?

SAML Configuration Form Overview
1. Enter the SP Entity ID in the provided text field.
2. Fill in the ACS URL field with the given API endpoint.
3. Upload the SP Certificate by clicking the "Upload SP Certificate" button.
4. Select "email" from the dropdown for SAMLSubject NameID.
5. Ensure the SAMLSubject NameID Format is set correctly.
6. Confirm the Signature Algorithm is set to RSA-SHA256.
7. Check the box for "Sign Assertion" if necessary.
8. Enter a value in the "Default RelayState" field as required.
9. Complete the "Login URL" field accordingly.
Session Duration attribute
It is now possible to add an attribute during the SAML configuration called SessionDuration. This value is essentially the number of seconds that we keep the authentication of the user valid after he/she has closed the Domotz App or WebApp.
The SessionDuration defines the validity of the token to authenticate in Domotz, considering the inactivity of the user himself.
This allows a user to keep its token valid for the Session Duration after his last operation within Domotz. For instance, if the user has configure the Session Duration for 2 days, the token used to authenticate within Domotz is always valid for the 2 days after his last operation within Domotz. After the 2 days, he will need to get a new valid token (by logging into the SAML/SSO system).
It is possible to configure the attribute on:
- Azure
- Jumpcloud
- Okta
Following, some screenshot on how to configure the SessionDuration attribute.
Azure

Edit Attributes and Claims Settings
1. Navigate to the "Attributes & Claims" section.
2. View the current mappings: "givenname" to "user.givenname," "surname" to "user.surname," "emailaddress" to "user.mail," "name" to "user.userprincipalname," "Unique User Identifier" to "user.userprincipalname."
3. To modify these settings, select the "Edit" option located in the upper right corner.

Add a New Claim in the Attributes & Claims Section
1. Navigate to the "Attributes & Claims" section.
2. Click on the "Add new claim" button, located at the top left corner, next to "Add a group claim."
3. In the "Required claim" section, notice the claim "Unique User Identifier (Name ID)" with the value "user.userprincipalname [nameid-format:emailAddress]."
4. Under "Additional claims," examine the list of claims such as "emailaddress" with value "user.mail," "givenname" with value "user.givenname," and more.
5. Use these details to configure or review claims as needed.

Manage a claim in a software interface.
1. Enter "SessionDuration" in the Name field.
2. Leave the Namespace field with a placeholder to enter a namespace URI.
3. Under Source, select the radio button for Attribute.
4. In the Source attribute field, enter the value "1800".

Additional Claims Configuration in a Software Interface
1. Navigate to the "Additional claims" section of the interface.
2. Locate the column headers: "Claim name" and "Value."
3. In the row labeled "SessionDuration," ensure the corresponding value is set to "1800."
4. The claim names include URLs for email, given name, name, and surname, each with associated user attributes such as user.mail, user.givenname, user.userprincipalname, and user.surname. These do not require changes if focusing on session duration.
This configuration will set the session duration to 1800 seconds.
Okta

Configuring an Attribute Statement.
1. Enter "SessionDuration" in the Name field.
2. Select "Unspecified" in the Name format dropdown.
3. Enter "1800" in the Value field.
4. Click "Add Another" to include additional attribute statements if needed.
Jumpcloud

Configuring SSO Settings in SAML 2.0
1. Navigate to the "SSO" tab within the SAML 2.0 section.
2. To enable SSO, ensure the "Declare Redirect Endpoint" checkbox is selected.
3. Enter the appropriate IDP URL, for example, "https://sso.jumpcloud.com/saml2/saml3".
4. In the "Attributes" section, specify user attributes by entering the "Service Provider Attribute Name" like "urn:oasis:names:tc:SAML:attribute:subject-id". Select the corresponding "JumpCloud Attribute Name" from the dropdown menu.
5. For constant attributes, input "SessionDuration" in the "Service Provider Attribute Name" and set its value to "2000".
6. Optionally, select the checkbox to include group attributes as needed.
7. Use the "Deactivate SSO" button to disable SSO settings whenever necessary.
Certificate Renewal
In case of a SSO/SAML certificate renewal please follow these steps.
1) Download the new generated Federation Metadata XML file:

Setting Up SAML-based Sign-on in Microsoft Azure
1. Navigate to the left panel under the "Manage" section and select "Single sign-on."
2. In the main window, locate the "SAML Signing Certificate" section.
3. Find and click the "Download" link for the certificate you need. This is crucial for configuring SAML-based authentication with your service provider.
4. Ensure other settings such as "Attributes & Claims" and "Sign-on URL" are correctly configured for your application's needs.
2) Access the Domotz app with a Team Leader account and go inside Account-> SAML/SSO Section:

Accessing and Managing Account Security Options
1. In the left sidebar menu, select the profile icon to navigate to your account page.
2. On the account page, locate the "Security" section. For SAML/SSO Identity Access Management, click the arrow icon beside the option to set up Domotz access through a third-party identity access management service.
click on the “Edit Configuration” button:

Setting Up SAML/SSO Configuration in Domotz
1. Navigate to the "SAML/SSO" tab in the portal settings.
2. Choose your Identity Provider by selecting one of the following options: Okta, Azure, JumpCloud, or Evo Security.
3. Enter the desired name for the configuration in the "Name" field. For example, "Domotz SSO."
4. Review the "SP Entity ID" and "SP Assertion Url" fields, which provide necessary URLs for the setup.
5. To test the current configuration, click on the "Test Configuration" button.
6. To make changes, select "Edit Configuration."
7. If needed, you can remove the current setup by clicking "Delete Configuration."
8. Ensure that the SAML Single Sign-On toggle is enabled for this user.
and then, click on “Upload metadata file”:

Configure SAML/SSO in Domotz Portal.
1. Navigate to the "SAML/SSO" tab in the security settings.
2. Choose your Identity Provider by selecting one of the options: Okta, Azure, JumpCloud, or Evo Security.
3. Enter a name for the configuration under "Name," e.g., "Domotz SSO."
4. Ensure the "SP Entity ID" and "SP Assertion Url" fields are filled with the appropriate URLs.
5. To upload your metadata file, select the "Upload metadata file" button found under "Upload Metadata."
6. Click "Update" to save your settings, or "Cancel" to discard changes.
If the configuration testing has succeeded (and only if your configuration testing has succeeded), you may click the “Update” button.