This feature is only available on Dub Enterprise.
For Dub Enterprise users, you can securely manage your team's access to Dub using Azure AD SAML SSO.
Step 1: Create or Select SAML Application
In your Azure Admin console, select Azure Active Directory (or search for it in the search bar).
data:image/s3,"s3://crabby-images/0f9e6/0f9e6765cbe7f65e39bc4cf91e2702cf0535ee77" alt="Azure Active Directory option on the Azure Dashboard"
Then, click on Enterprise applications from the left sidebar.
data:image/s3,"s3://crabby-images/f059b/f059b3271496b4cf725b420f777bbbc53cad1641" alt="Enterprise applications option on the Azure Dashboard"
If you already have an existing Azure AD SAML application, select it from the list and move on to Step 2.
If not, click on New application at the top.
data:image/s3,"s3://crabby-images/11f92/11f920e1c254d5399e46287bd0d3b6552e39c7c6" alt="Create new application button on the Azure Dashboard"
In the next screen, click on Create your own application. Give your application a Name (e.g. "Dub") and click Create.
data:image/s3,"s3://crabby-images/b78a8/b78a8024a975022db56039b6f4d5dc5c946902cb" alt="Create your own application option on the Azure Dashboard"
Step 2: Configure SAML Application
Under the Manage section in the left sidebar, select Single sign-on. Then, click on SAML.
data:image/s3,"s3://crabby-images/f3460/f3460032e5bdf98fb3af4b7929441239e5f99de6" alt="SAML option on the Azure Dashboard"
Under the Basic SAML Configuration section, click on Edit.
data:image/s3,"s3://crabby-images/8c8f1/8c8f18e167765fdff6eb6f8acfd9594d7f0089d5" alt="Edit button on the SAML Settings page on the Azure Dashboard"
This will open up a sheet overlay. Under Basic SAML Configuration, enter the following values:
Identifier (Entity ID)
Reply URL (Assertion Consumer Service URL)
data:image/s3,"s3://crabby-images/dfc73/dfc73b7c7423cbb0b942ef4483bf23710b2bd215" alt="Basic SAML Configuration section on the Azure Dashboard"
Click Save in the menu bar to save your changes.
data:image/s3,"s3://crabby-images/7984b/7984b3d0e1ebfa87d6cf15c0bc4943f947475e64" alt="Basic SAML Configuration section on the Azure Dashboard"
Step 3: Attribute Mapping
Click Edit on the Attributes & Claims section.
data:image/s3,"s3://crabby-images/c485b/c485b1d0008e211dad250a1e03bdeab4eb94e202" alt="Attributes & Claims section on the Azure Dashboard"
Under Additional claims, make sure the following entries are present:
Name | Value |
---|---|
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress | user.mail |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname | user.givenname |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name | user.userprincipalname |
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname | user.surname |
data:image/s3,"s3://crabby-images/a8475/a84751df0a3a74721903aa73e485e784c202039f" alt="Additional claims section on the Azure Dashboard"
Once that's done, click on the X
button in the top right corner to go back to the main settings page (or click the back button in your browser).
Step 4: Copy the Metadata URL
Scroll down to the 3rd section on the page, SAML Certificates. Copy the App Federation Metadata Url value and return to the Dub dashboard.
data:image/s3,"s3://crabby-images/74cce/74cce4b71b6ffa1367716e8bd6eca7e255033b9a" alt="Metadata URL on the Azure Dashboard"
Step 5: Configure SAML SSO on Dub
In your workspace dashboard on Dub, click on the Settings tab in the menu bar at the top. Then, click on the Security tab in the sidebar.
data:image/s3,"s3://crabby-images/8135c/8135c551ba047c1d9e135bd323d96af81d5af1cd" alt="SAML SSO section on the Dub Dashboard"
Under the SAML Single Sign-On section, click on Configure. This will open up the SAML SSO modal:
- Select Azure AD as the SAML provider.
- Enter the App Federation Metadata Url value that you copied from Step 4.
- Click Save changes.
data:image/s3,"s3://crabby-images/09d00/09d00e34dab1e9dac0cc348f79954966de02b448" alt="SAML SSO Modal"
Step 6: Assign Users
We highly recommend configuring SCIM Directory Sync before assigning users & groups to your workspace. This will ensure that your users are automatically added to your workspace when they sign in for the first time, as well as automatically removed when they are deactivated in Azure.
Once you've configured SAML SSO, you can start assigning users & groups to your workspace.
From your application, click the Users and groups from the left navigation menu and click Add user/group.
data:image/s3,"s3://crabby-images/4fe9a/4fe9a516b7b909b713600a59e360087df621eb4c" alt="Adding users in Azure AD"
Click on None Selected under Users.
From the right side of the screen, select the users you want to assign to the app and click the Select button. Thenm click Assign to those users to your app.
data:image/s3,"s3://crabby-images/a97f5/a97f5cd0acf92f7c6a02f23565403112d2896001" alt="Assigning users in Azure AD"
Your assigned users should now receive an invitation email to join your Dub workspace.
data:image/s3,"s3://crabby-images/1ede6/1ede657ed55c010b70c25570b75a7f6f19e01d07" alt="SAML invite email"
Azure AD SCIM provisioning can take anywhere between 20-40 minutes to sync. This means that it may take up to 40 minutes for your users to receive the invitation email and be able to join your Dub workspace.
They will also be able to sign in to Dub using Azure AD SSO.