SAML 2.0
Official protocol documentation https://saml.xml.org/saml-specifications
Supported features
- SSO (SP initiated flow & IdP initiated flow)
- Updating user data by SSO with data from SAML assertion
Setup requirements
- SSO endpoint url
- signing certificate
- NameID configuration
- names of assertion attributes that will contain: email, first name and last name
- optional: names of assertion attribute that will contain: department name
Error reporting
To help us to provide support in case of any issues, please attach following data to error report:
- requirements
- error message
- date and time of error occurrence (with time zone)
- nice to have
- SAML assertion related to error
- screen recording
- app error screenshots
- browser console error screenshots
Resources
Microsoft Learn - Set up a SAML 2.0 provider with ADFS
Azure SSO (Entra) setup instruction EN
Azure SSO (Entra) setup instruction DE
SAML certificates
Signing certificate — Allows your identity provider to verify SAML requests signed by Masterplan.
- Entra/SHA-1 thumbprint:
140406E19A3C0401BAE5E738272FBA749C78FDC8 - SHA-256 fingerprint:
5C:24:7F:01:8E:BD:D8:82:21:CA:AA:E2:BE:E8:01:38:C5:A3:93:49:60:46:48:15:55:52:DA:49:25:C3:05:E6 - Expires: September 22, 2036 at 18:32:43 UTC
- Entra/SHA-1 thumbprint:
Encryption certificate — Allows your identity provider to encrypt SAML assertions that only Masterplan can decrypt.
- Entra/SHA-1 thumbprint:
FF9D123B1F8C74702A7D495008DE0647FDB99D16 - SHA-256 fingerprint:
5B:35:45:DD:61:AE:F3:7B:D1:F4:CB:FF:33:F9:26:6D:38:86:19:6F:09:B9:42:CA:98:F0:CF:D9:25:AE:04:0F - Expires: September 22, 2036 at 18:35:19 UTC
- Entra/SHA-1 thumbprint:
⚠️ Warning: deprecated certificate
Deprecated certificate — Supports legacy Masterplan SAML configurations in which this certificate may have been used for signing, encryption, or both.
Entra/SHA-1 thumbprint:
135515583381ACD2B495B02AF47D8770B28AFC5ASHA-256 fingerprint:
8C:2A:0D:FB:5A:1E:F3:83:72:0A:EC:DF:3B:F8:C0:64:EA:B5:A7:D5:F8:E8:EA:BA:D8:7A:DA:62:FC:CF:08:63Expires: October 15, 2026 at 23:59:59 UTC
Before this certificate expires, add the current signing certificate and, if your configuration uses the deprecated certificate for encryption, the current encryption certificate. Keep the deprecated certificate alongside the new certificate or certificates until it has expired to prevent SAML SSO interruptions.
Frequently asked questions
How to initiate SSO?
Users can be directed to Masterplan involving SSO in two ways:
-
using SSO initiation page specific for your company:
e.g.
https://masterplan.com/sso/your_company_sso_id -
using SSO Launch Link related to specific content:
e.g.
https://masterplan.com/launch?content_id=...&content_type=...&source_id=...
How users are linked between Masterplan and client system?
In order to link users between Masterplan and your system, a unique identifier is essential. We strongly recommend utilizing a global user id and advise against relying solely on user email addresses. This approach ensures the automatic synchronization of user emails in Masterplan, even in the event of changes made on the client side.
Will new user accounts be created during inaugural SSO login?
New user accounts will be automatically generated during their inaugural SSO login, provided that the company owner account has available free licenses allocated for new user assignments.