This article uses Microsoft Entra ID, a third-party tool. We aim to keep these details accurate, but we can't guarantee they're always complete or up to date. For the most reliable information, refer to the Microsoft Entra documentation.
There are two ways to log in to Lansweeper Platform: with a login and password created in Lansweeper Platform itself, or with SSO. SSO is supported for identity providers that offer SAML (Security Assertion Markup Language) or OIDC (OpenID Connect). Microsoft Entra ID (Azure AD) is one such identity provider (IdP).
This article covers where in Microsoft Entra ID (Azure AD) to find the SSO connection details you enter in Lansweeper Platform, using SAML as the connection type. Read Set up an SSO connection first.
In Lansweeper Platform, you exchange these values in the SSO connection itself. Select your profile picture in the top-right corner, select Account settings > Single Sign-On, then select Create SSO connection. The Service provider metadata section holds the values you copy into Entra ID, and the Identity provider configuration section is where you enter the values you get back from Entra ID.
For more about securing your Lansweeper account, see 5 Features of Lansweeper Cloud that Strengthen Security.
Create an application in Microsoft Entra ID (Azure AD)
- Log in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
- Browse to Entra ID > Enterprise apps > All applications and select New application.
- Select Create your own application.
- In the resulting pane, enter a descriptive name for your application and select Integrate any other application you don't find in the gallery (Non-gallery).
- Select Create.
Configure your SSO app
- In the Manage section of your new app's left menu, select Single sign-on, then select SAML.
- Select Edit in the Basic SAML Configuration section.
- Copy the Entity ID from the Service provider metadata section in Lansweeper. Paste it into the Identifier (Entity ID) field and set it as the default.
- Copy the Assertion Consumer Service (ACS) URL from the Service provider metadata section in Lansweeper and paste it into the Reply URL (Assertion Consumer Service URL) field.
- Copy the SingleLogout Service (SLO) URL from the Service provider metadata section in Lansweeper and paste it into the Logout Url field.
- Select Save.
- In the SAML Certificates section, select Download next to Certificate (Base64). Upload the file as the X509 signing certificate in the Identity provider configuration section in Lansweeper.
- In the Set up <your app name> section, copy the Login URL.
- Paste it into the Sign in URL field in the Identity provider configuration section in Lansweeper. Optionally, you can also copy the Logout URL from Microsoft Entra ID (Azure AD) to Lansweeper.
- In the Attributes & Claims section, check that the
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddressclaim is mapped touser.mail. Microsoft Entra ID includes this claim by default, and it matches the default Email claim in Lansweeper. If you map the email address to a different claim, enter that claim name in the Email claim field in Lansweeper. - In the Manage section of your app's left menu, select Users and groups, then select Add user/group.
- Select the users and groups that can log in to Lansweeper Platform using SSO. As a Microsoft Entra ID (Azure AD) admin, you can monitor your users' SSO logins in Microsoft Entra ID (Azure AD).