π 1: Enable single sign-on with SAML
In Microsoft Entra ID, go to your
Enterprise Applicationfor Company ShieldClick on
Single sign-onβSAML
π§βπ§ 2. Configure SAML URLs
Click on
Editnext toBasic SAML ConfigurationIn a separate tab, open the revel8 dashboard and go to Settings β Integrations β Access Controls tab
Copy and paste the following:
Entity IDβ Paste in Microsoft Entra from revel8'sEntity IDReply URL (ACS)β Paste in Microsoft Entra from revel8's ACS URL
4. Click Save in the Microsoft Entra portal
βοΈ 3: Install SAML Certificate
In the
SAML Certificatessection of Microsoft Entra: Click Download next toFederation Metadata XMLGo back to revel8 β Settings β Integrations β Access Controls tab: Upload the downloaded
.xmlfile in theMetadata filesection
π 4: Attributes and Claims
In most cases, default settings work without changes. If needed, go to the Attributes and Claims section to adopt the standard setting.
πΉ http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname (optional)
πΉ http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name (optional)
πΉ http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname (optional)
β 5: Assign Users and Groups
Go to Users and groups β click Add user/group, and select your users.
π 6: Group to Role Mappings (Optional)
Once SAML is active, you can automatically assign revel8 roles based on your Entra ID groups. This eliminates the need to manually assign roles to each user after login.
In revel8, go to Settings β Integrations β Access Controls tab
Scroll to the Group to Role Mappings section
Click Add Mapping to add a new row
Enter the IdP Group Name exactly as it appears in your Entra ID
Select the corresponding revel8 role from the dropdown:
EMPLOYEE,EDITOR,CISO, orDIRECTORRepeat for each group you want to map, then click Save Mappings
π‘ Tip
You can add multiple mappings. Users in a mapped group will automatically receive that role upon login. Users not matched to any mapping default to the EMPLOYEE role.
π‘οΈ 7: Disable Password Login (Optional)
Once SAML is active, you can optionally disable password-based login to enforce SSO as the only login method for your organization.
In revel8, go to Settings β Integrations β Access Controls tab
Under the SAML status section (visible once SAML is active), check the Password login disabled checkbox
β
β οΈ Important
Disabling password login means users can only log in via SAML SSO. Ensure your SAML configuration is fully tested before enabling this to avoid locking users out.
β Final Checklist
SAML URLs configured in Microsoft Entra
Metadata file downloaded from Entra and uploaded to revel8 via Settings β Integrations β Access Controls
Attributes and Claims checked
Users and Groups assigned in Entra
Group to Role Mappings configured (optional)
Password login disabled if enforcing SSO-only (optional)
Test login successful










