How to set Microsoft Entra ID with Single-Sign-On by SAML


You can also check with Microsoft’s official Tutorial: Azure AD SSO integration with BenQ IAM as a reference.

Prerequisites

  1. A Microsoft Entra ID subscription.
  2. A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  3. register benq account

Add BenQ IAM as enterprise application

To configure the integration of BenQ IAM into Microsoft Entra ID, you need to add BenQ IAM from the Microsoft Entra Gallery to your list of managed SaaS apps.

  1. Sign in to the Azure portal using either a work or school account, or a personal Microsoft account.
  2. On the left navigation pane, select the Microsoft Entra ID service.
  3. Select the Microsoft Entra ID service
  4. Navigate to Enterprise Applications and then select All Applications.
  5. Navigate to Enterprise Applications and then select All Applications
  6. To add new application, select New application.
  7. In the Microsoft Entra Gallery section, type BenQ IAM in the search box.
  8. In the Microsoft Entra Gallery section, type BenQ IAM in the search box
  9. Select BenQ IAM from results panel and then add the app. Wait a few seconds while the app is added to your application list.

Configure Microsoft Entra ID SSO

Follow these steps to enable Microsoft Entra ID SSO in the Azure portal and BenQ IAM

  1. Login BenQ IAM with BenQ Admin Account, click SSO Setting in the Account Management section.
  2. Entry point to SSO setting
  3. Select SAML as SSO Setting in the pop up.
  4. Select SAML as SSO Setting
  5. Fill up your organization name as the “Organization Unit”.
  6. Login the Azure portal, on the BenQ IAM application integration page click Set up single sign-on.
  7. Set up single sign-on
  8. On the Single sign-on method page, select SAML.
  9. Select SAML as Single sign-on method
  10. On the Set up single sign-on with SAML page, click the pencil icon for Basic SAML Configuration to edit the settings.
  11. Edit Basic SAML Configuration
  12. Copy text listed on IAM to fill up the required information:
    • Copy the Identifier URL on BenQ IAM and paste it to the Identifier text box in Azure Portal
    • Copy the Reply URL on BenQ IAM and paste it to the Reply URL text box in Azure Portal
    • In the Azure Portal- Logout URL text box, type the following url: https://service-portal.benq.com/logout
    • Fill up the required information for Basic SAML Configuration
    • After filling the previous setting, click Save for Basic SAML Configuration.
  13. Next, click the pencil icon for Attributes & Claims to edit attributes.
  14. Edit Attributes & Claims
  15. Add new claim for firstName and lastName
  16. Add new claim for firstName and lastName
  17. Fill up firstName in Name field and define the source attribute as user.givenname
  18. Fill up firstName in Name field and define the source attribute as user.givenname
  19. Fill up lastName in Name field and define the source attribute as user.surname
  20. Fill up lastName in Name field and define the source attribute as user.surname
  21. Remember click “Save” button to complete the revision.
  22. Then you could find the Login URL, Identifier and Certificate on Azure. Please copy and paste to IAM accordingly.
  23. Copy and paste the Login URL, Identifier and Certificate to IAM
    • On the Set up BenQ IAM section, type the name in the Organization Unit text box that can represent your organization
    • Copy the Login URL in Azure Portal and paste it to the login/SSO URL text box in BenQ IAM
    • Copy the Azure AD Identifier in Azure Portal and paste it to the Identifier/Entity ID text box in BenQ IAM
    • On the Set up single sign-on with SAML page of Azure Portal, in the SAML Signing Certificate section, find Certificate (Base64) and select Download to download the certificate and save it on your computer. Open the Certificate (Base64), copy and paste it to the Certificate (Base64) text box in BenQ IAM
  24. After filling the previous setting, remember to select Available service settings by preference and click Save.
  25. BenQ IAM will show the success message as below image. Then, you can go further to configure BenQ IAM for automatic user provisioning.
  26. BenQ IAM will show the success message

Continue to check how to configure BenQ IAM for automatic user provisioning

Configure BenQ IAM for automatic user provisioning


You can also check with Microsoft’s official Tutorial: Configure BenQ IAM for automatic user provisioning

  1. Following the results in How to set Microsoft Entra ID with Single-Sign-On chapter. In the success message windows of BenQ IAM, please, click Create Token.

    Create Token to enable automatic user provisioning

  2. Copy the token. Please keep this token carefully, it will be used in the Azure portal later.

    Copy the token and used in the Azure portal later

  3. Back to Azure portal, on the BenQ IAM application integration page, find the Manage section and select Provisioning.

  4. Set the Provisioning Mode to Automatic.

    Set the Provisioning Mode to Automatic

  5. Under the Admin Credentials section. About the tenant URL Please enter the url - https://service-portal.benq.com/api/scim/v2

  6. About the secret token, fill in the token that generated in Step1.

    Fill in the token that generated in Step1

  7. In the Notification Email field, enter the email address of a person or group who should receive the provisioning error notifications and select the Send an email notification when a failure occurs check box.

  8. Select Save.

Mapping the attribute for provision

To ensure the data of Microsoft Entra ID display correctly in IAM, please mapping the attribute according to the steps below:

  1. Enable the capability to edit the list of supported attributes by navigating to the following URL: https://portal.azure.com/?Microsoft_AAD_Connect_Provisioning_forceSchemaEditorEnabled=true
  2. Go to BenQ IAM application overview and click “Provision User Accounts”
  3. Go to BenQ IAM application overview and click Provision User Accounts
  4. Click “Attribute mapping”
  5. Click Attribute mapping
  6. Click “Provision Microsoft Entra ID Users” under the “Mappings” section
  7. Click Provision Microsoft Entra ID Users under the Mappings section

    Scroll down the page to find “Show advanced options” check box and tick it, advanced options will appear. Click on “Edit attribute list for BenQIAM”
    Scroll down the page to find Show advanced options check box and tick it, advanced options will appear. Click on Edit attribute list for BenQIAM
  8. Add name.givenName, name.familyName, title, addresses[type eq "work"].formatted column and set as String type. Click check box to set as Required columns and Save.
  9. Add name.givenName, name.familyName, title, addresses[type eq
  10. You will be navigated to the Attribute Mapping page after saving the revision. Now you can click “Add New Mapping”
  11. You will be navigated to the Attribute Mapping page after saving the revision. Now you can click Add New Mapping
  12. Now you can associate Source attribute and Target attribute.
    1. Select source attribute as givenName, and name.givenName as target attribute.
    2. Select source attribute as surname , and name.familyName as target attribute.
    3. Select source attribute as jobtitle, and title as target attribute.
    4. Select source attribute as physicalDeliveryOfficeName, and addresses[type eq "work"].formatted as target attribute. This attribute corresponds to User property > Job information > Office location
  13. Now you can associate Source attribute and Target attribute. 1. Select source attribute as givenName, and name.givenName as target attribute. 2. Select source attribute as surname , and name.familyName as target attribute. 3. Select source attribute as jobtitle, and title as target attribute. 4. Select source attribute as physicalDeliveryOfficeName, and addresses[type eq Job information > Office location" src="../images/sso_manual/saml_configuration/scim-job-position.png?version=v2.5.1.2">

    Select source attribute as givenName, and name.givenName as target attribute

    Select source attribute as surname , and name.familyName as target attribute

    Select source attribute as physicalDeliveryOfficeName, and addresses[type eq Job information > Office location" src="../images/sso_manual/saml_configuration/scim-mapping-location.png?version=v2.5.1.2">

    Select source attribute as jobtitle, and title as target attribute
  14. Check the attribute mapping table again and click ”Save” to complete the mappings.
  15. Check the attribute mapping table again and click ”Save” to complete the mappings.

How to set Google Workspace with Single-Sign-On by SAML


Prerequisites

  1. A Google Workspace subscription.
  2. A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  3. register benq account

Configure Google Workspace SSO

Follow these steps to enable Google Workspace SSO in Google Workspace and BenQ IAM.

  1. Visit Google Workspace > Google Admin (https://admin.google.com/).
  2. Under Apps > Overview > select Web and mobile apps section
  3. Under Apps > Overview > select Web and mobile apps section
  4. Select Add App > Add custom SAML app
  5. Select Add App > Add custom SAML app
  6. Type BenQ IAM in the App name text box, then click CONTINUE
  7. Type BenQ IAM in the App name text box, then click CONTINUE
  8. On the Google Identity Provider details section, we choose Option 2 to do SSO integration by performing the following steps
    • Login BenQ IAM with BenQ Admin Account, click SSO Setting in the Account Management section.
    • Entry point to SSO setting
    • Select SSO by SAML as SSO Setting in the pop up.
    • Select SSO by SAML as SSO Setting
    • On the Set up BenQ IAM section, type the name in the Organization Unit text box that can represent your organization
    • Copy the SSO URL in Google Workspace and paste it to the login/SSO URL text box in BenQ IAM
    • Copy the Entity ID in Google Workspace and paste it to the Identifier/Entity ID text box in BenQ IAM
    • Copy the Certificate in Google Workspace and paste it to the Certificate (Base64) text box in BenQ IAM
    • Copy the Certificate in Google Workspace and paste it to the Certificate (Base64) text box in BenQ IAM
    • Click Continue in Google Workspace
  9. On the Service provider details section
  10. On the Service provider details section
    • Copy the Identifier URL in BenQ IAM and paste it to the Entity ID box in Google Workspace.
    • Copy the Reply URL in BenQ IAM and paste it to the ACS URL box in Google Workspace.
  11. On the Attribute mapping section, there are some attributes need to be mapped.
    • Choose Google Directory Attributes and map it with App attributes as bellow table
    • Table listing Google Directory Attributes mapped to App attributes: First name to firstName, Last name to lastName, Primary email to email, and First name to displayName
      SAML attribute mapping page in Google Admin console showing Google Directory attributes mapped to App attributes for First name, Last name, Primary email and displayName
    • If mapping the group attributes to BenQ IAM is needed, please choose the Google groups you need to propagate to BenQ IAM and map it with groups. (Optional)
    • Group membership section in Google Admin console mapping selected Google groups to the App attribute groups
    • Then, click FINISH.
  12. Now, the SSO integration with Google Workspace has been set successfully. Please make sure the users under your directory have permission to login BenQ IAM by checking User access section in Google Workspace. You can permit access permissions by organizational units, groups or individuals. Then, it can make sure that only the authorized users can login to BenQ boards and services.
  13. Now, the SSO integration with Google Workspace has been set successfully. Please make sure the users under your directory have permission to login BenQ IAM by checking User access section in Google Workspace. You can permit access permissions by organizational units, groups or individuals. Then, it can make sure that only the authorized users can login to BenQ boards and services.
  14. If the new groups needs to be propagated to BenQ IAM, please go to SAML attribute mapping section and add the Google groups in Google membership.
  15. If the new groups needs to be propagated to BenQ IAM, please go to SAML attribute mapping section and add the Google groups in Google membership.

How to set Okta with Single-Sign-On by SAML


For the latest information of Okta SAML settings, please refer to Okta website: https://support.okta.com/help/s/?language=en_US

Prerequisites

  1. An Okta subscription.
  2. A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  3. register benq account

Configure BenQ IAM as a SAML Application

To configure the integration of BenQ IAM into Okta, you need to create an SAML v2.0 app integration in Okta admin console.

  1. Login BenQ IAM with BenQ Admin Account, click SSO Setting in the Account Management section
  2. Entry point to SSO setting
  3. Select SAML as SSO Setting in the pop up
  4. Select SAML as SSO Setting
  5. Fill up your organization name as the Organization Unit.
  6. Sign in to the Okta Admin Console.
  7. On the left navigation pane, select the Applications.
  8. On the left navigation pane, select the Applications
  9. Click on Create App Integration. And choose SAML 2.0 as Sign-in method.
  10. Click on Create App Integration. And choose SAML 2.0 as Sign-in method.
  11. Fill up the App name, for example BenQ IAM.
  12. Fill up the App name, for example BenQ IAM.
  13. Copy text listed on IAM to fill up the required information:
    • Copy the Identifier URL on BenQ IAM and paste it to the Audience URI (SP Entity ID) text box in Okta Portal
    • Copy the Reply URL on BenQ IAM and paste it to the Single sign-on URL text box in Okta
    • Copy the Reply URL on BenQ IAM and paste it to the Single sign-on URL text box in Okta
  14. On the Attribute Statements, map the attribute as following then finish the settings.
  15. On the Attribute Statements, map the attribute as following then finish the settings.
  16. Then you can find the Sign on URL, Issuer and Signing Certificate. Please copy and paste to IAM accordingly.
  17. Then you can find the Sign on URL, Issuer and Signing Certificate. Please copy and paste to IAM accordingly.
    • On the Set up BenQ IAM section, type the name in the Organization Unit text box that can represent your organization
    • Copy the Sign on URL and paste it to the login/SSO URL text box in BenQ IAM
    • Copy the Issuer and paste it to the Identifier/Entity ID text box in BenQ IAM
    • Copy the Signing Certificate and paste it to the Identifier/Entity ID text box in BenQ IAM
  18. After filling the previous setting, remember to select Available service settings by preference and click Save.
  19. After setup, remember to assign the application to the users you wish to sync with BenQ IAM. Navigate to Assignments > Assign > Assign to People/Group and select the desired members.
  20. After setup, remember to assign the application to the users you wish to sync with BenQ IAM. Navigate to Assignments > Assign > Assign to People/Group and select the desired members.

How to set Microsoft Entra ID with Single-Sign-On and user auto-provisioning

Prerequisites

  • A Microsoft Entra ID subscription.
  • A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  • register benq account

Configure Microsoft Entra (OAuth) SSO

Follow these steps to enable Microsoft Entra (OAuth) SSO in BenQ.

  1. Login BenQ IAM with BenQ admin account, click SSO Setting in the Account Management section.
  2. Entry point to SSO setting
  3. Select Microsoft Entra (OAuth) in the pop up.
  4. Select Azure as SSO Setting
  5. Enable service and configure permission for members.
  6. Choose services default role
  7. Login or choose you Microsoft365 administrator account.
  8. Pick account to login
  9. Click Accept to grant the access.
  10. Accept permissions requested
  11. Click Set up under Synchronization settings. Choose whether to import, update, or delete accounts.
  12. Set up synchronization settings Select synchronization actions
  13. Click Set up under Import account settings. This setting lets you sync the domain you prefer and import all accounts or specific groups from Microsoft Entra ID. By default, BenQ IAM will import all accounts from the primary domain. If you are satisfied with the default settings, you can skip to step 8.
  14. If you select Import by group, please fill in and add the group name you want according to Microsoft Azure Portal.
  15. Select group name to import
  16. Click Apply.
  17. Enable Automatic synchronization to activate user auto-provisioning from your Microsoft Entra ID.
  18. Switch to enable Automatic synchronization
  19. Click Sync now to finish the settings.
  20. Start to synchronize

How to set Google Workspace with Single-Sign-On and user auto-provisioning

Prerequisites

  • A Google Workspace subscription.
  • A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  • register benq account

Configure Google Workspace SSO

Follow these steps to enable Google Workspace SSO in BenQ.

  1. Login BenQ IAM with BenQ admin account, click SSO Setting in the Account Management section.
  2. Entry point to SSO setting
  3. Select Google Workspace Settings in the pop up.
  4. Select Google Wrokspace as SSO Setting
  5. Login or choose you Google Workspace administrator account.
  6. Choose an account to login
  7. Click Allow to grant the access.
  8. Accept permissions required
  9. Enable Group Synchronization to sync Google Workspace groups to IAM Groups.
  10. Switch to enable group synchronization
  11. Click Set up under Import account settings. This setting lets you sync the domain you prefer and import all accounts or specific groups from Google Workspace. By default, BenQ IAM will import all accounts from the primary domain. If you are satisfied with the default settings, you can skip to step 11.
  12. Set up imported setting
  13. You can choose the domain you want and select either Import all accounts or Import by group.
  14. Import all
  15. If you select Import by group, please fill in and add the group email you want according to Google Admin Console.
  16. Import by group email
  17. Click Apply.
  18. Apply the imported setting
  19. Enable Automatic synchronization to activate user auto-provisioning from your Google Workspace directory.
  20. Switch to enable Automatic synchronization
  21. Click Sync now to finish the settings.
  22. Start to synchronize

How to set up ClassLink with Single-Sign-On?

Prerequisites

  • A ClassLink subscription.
  • A BenQ IAM administrator account. Please follow the normal steps to register a BenQ IAM admin account.
  • register benq account

Configure ClassLink SSO

Follow these steps to enable ClassLink SSO in ClassLink and BenQ.

  1. Login BenQ IAM with BenQ admin account, click SSO Setting in the Account Management section.
  2. Entry point to SSO setting
  3. Select SSO by ClassLink as SSO Setting in the pop up.
  4. Select Classlink as SSO Setting
  5. Please configure default user role for imported accounts
  6. Choose services default role
  7. Then, click Next to enter ClassLink login page.
  8. Login your ClassLink account.
  9. If you’d like to import users from OneRoster, please follow the next chapter. If not, please click save to complete settings.

How to set up ClassLink SSO OneRoster connection?

  1. Go to https://launchpad.classlink.com/ , login with administrator account.
    In Roster Server management console > Add New App, search for BenQ IAM and add it.
  2. Select BenQ IAM to add new App
  3. Let us find the information we need here to complete the setup in BenQ SSO.
    These are Client ID and Client Secret .
    Under Applications > BenQ IAM > API, you can find Key(Client ID) and Secret(Client Secret) .
  4. Found out API credentials of application
  5. In SSO setting for ClassLink , user can enable One Roster connection as below.
    Fill in Client ID and Client Secret to complete the OneRoster configuration.
  6. Copy the key and secret then paste on client ID and client secret
  7. BenQ IAM will show message as below, click Sync now to start syncing users.
  8. BenQ IAM will show connection status
  9. Once you see below dialog, the sync task is now queued and will run in background, you can close below dialog by click X button in the top right corner, and continue other management tasks.
  10. Start to synchronize
  11. Revisit this dialog later by go to SSO setting > ClassLink as below:
  12. Open Classlink sso setting
  13. Sync status will be displayed as below:
  14. Sync status is shown after synchronized finish

How to set up Clever with Single-Sign-On

Prerequisites

  • A Clever subscription, user account and password.
  • District ID / School Name or School ID for your organization.
  • register benq account

Configure Clever SSO

Follow these steps to enable Clever SSO in BenQ.

  1. Login BenQ IAM with BenQ admin account, click SSO Setting in the Account Management section.
  2. Entry point to SSO setting
  3. Select Clever as SSO Setting in the pop up.
  4. Select Clever as SSO Setting
  5. Please fill in your Clever District ID , set the default BenQ service role, then, click Save.
  6. Choose services default role
  7. BenQ IAM will display a success message and a confirmation dialog below. Due to Clever’s workflow, district connection requires approval from the BenQ team, which typically takes 1–2 business days. Once approved, your shared data will connect automatically.
  8. Configuration saved successfully