SAML 2.0
Official protocol documentation https://saml.xml.org/saml-specifications
Supported features
- SSO (SP initiated flow & IdP initiated flow)
- Updating user data by SSO with data from SAML assertion
Setup requirements
- SSO endpoint url
- signing certificate
- NameID configuration
- names of assertion attributes that will contain: email, first name and last name
- optional: names of assertion attribute that will contain: department name
Error reporting
To help us to provide support in case of any issues, please attach following data to error report:
- requirements
- error message
- date and time of error occurrence (with time zone)
- nice to have
- SAML assertion related to error
- screen recording
- app error screenshots
- browser console error screenshots
Resources
Azure SSO (Entra) setup instruction EN
Azure SSO (Entra) setup instruction DE
Frequently asked questions
How to initiate SSO?
Users can be directed to Masterplan involving SSO in two ways:
-
using SSO initiation page specific for your company:
e.g.
https://masterplan.com/sso/your_company_sso_id
-
using SSO Launch Link related to specific content:
e.g.
https://masterplan.com/launch?content_id=...&content_type=...&source_id=...
How users are linked between Masterplan and client system?
In order to link users between Masterplan and your system, a unique identifier is essential. We strongly recommend utilizing a global user id and advise against relying solely on user email addresses. This approach ensures the automatic synchronization of user emails in Masterplan, even in the event of changes made on the client side.
Will new user accounts be created during inaugural SSO login?
New user accounts will be automatically generated during their inaugural SSO login, provided that the company owner account has available free licenses allocated for new user assignments.