Integrations

/

Microsoft AD FS SAML2 SSO with Flexopus

Secure single sign-on for your on-premise environment – seamlessly integrated into Flexopus.

No items found.
No items found.

What is the Microsoft AD FS SAML2 SSO integration?

Microsoft Active Directory Federation Services (AD FS) is an identity provider solution developed by Microsoft for organizations that manage their user identities locally (on-premises). AD FS can be used as a central authentication service for external applications via the SAML2 protocol (Security Assertion Markup Language).

Flexopus supports integration with Microsoft AD FS via SAML2. This means that your employees can log in to Flexopus using their existing company login details – without an additional password. The connection is established via a so-called Relying Party Trust in the AD FS console, with Flexopus being entered as a trusted application.

Additionally, user attributes such as name, email address, department and job title can be transferred from Active Directory to Flexopus. Optionally, group synchronization is also possible via the SAML2 attribute "memberOf".

What is the purpose of integration?

The AD FS SAML2 SSO integration connects your existing on-premise identity management directly to Flexopus. Typical use cases include:

  • Central login: Employees log in to Flexopus with their Windows login credentials – no separate account is necessary.
  • Automatic user creation: New users are automatically registered in Flexopus upon their first login, without any manual preparation by administrators.
  • Attribute transfer: Profile fields such as first name, last name, email, department and job title are taken directly from the Active Directory.
  • Group synchronization: Active Directory groups can be passed to Flexopus via the SAML2 attribute "memberOf" and managed there as external groups.
  • Access control: In the AD FS console, you determine which users or groups are granted access to Flexopus.

Especially for companies that operate a hybrid Active Directory architecture, Flexopus recommends performing the integration directly via the cloud-based Microsoft Entra ID (formerly Azure Active Directory) – provided that the user data is synchronized there.

How easy is the integration?

Setup is completed in a few steps via the AD FS management console and the Flexopus dashboard. Essentially, Flexopus is registered as a relying party in AD FS, the desired user attributes are configured as claims, and then the metadata URL is stored in Flexopus.

After configuration, you can test the login directly in the browser. Optionally, the classic email/password login can be deactivated to enforce SSO as the only login option.

For complete step-by-step setup instructions, please visit our Help Center.

What are the advantages of integration?

  • No additional password required: Employees use their existing company login credentials – this reduces password management effort and increases security.
  • Automatic user registration: New users are automatically created upon their first login – without manual setup by administrators.
  • Central access control: The control over who is allowed to log in to Flexopus is done directly via the AD FS policies.
  • Attribute transfer included: Profile information such as name, email, department and job title are automatically synchronized.
  • Optional group synchronization: Active Directory groups can be passed to Flexopus via SAML2 to efficiently manage access rights.
  • Two-factor authentication: The 2FA settings from Microsoft are automatically applied – no duplicate configuration is necessary.
  • Included free of charge: SSO integration is part of Flexopus and requires no additional license fees.
  • Flexible configuration options: Two configuration methods (Custom Rule or LDAP Attributes) are available to adapt to different AD FS setups.
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

Which user data is transferred from Active Directory to Flexopus?

Only the attributes defined within the SAML2 configuration are transferred. By default, these are: User Principal Name (UPN), Display Name, First Name, Last Name and Email Address. Optionally, department and job title can also be transmitted. No further data will be retrieved from Active Directory.

What happens when a user is deleted or disabled from Active Directory?

If a user is disabled or deleted in AD FS, they will no longer be able to log in to Flexopus. Since authentication is performed via AD FS for every login, access is immediately blocked. However, the user remains in Flexopus until they are manually deleted or deactivated there. We recommend cleaning up user accounts in Flexopus as well to ensure a consistent database.

Can I use SSO and the classic email/password login at the same time?

Yes, by default both login options can be used in parallel. After successful SSO setup, you have the option to disable email/password login or hide the login form to enforce SSO as the only login method. This setting can be adjusted at any time – even retroactively by the Flexopus support team.

What if my AD FS server is only accessible on the internal network?

If your AD FS server is not publicly accessible, Flexopus cannot automatically retrieve the metadata URL. In this case, we recommend manually uploading the metadata as a file to Flexopus. Please note that if changes are made to certificates or signatures, the metadata file must be updated manually. Such changes are usually necessary every 3-5 years and can be implemented quickly.

Does the integration also support two-factor authentication (2FA)?

Yes. Two-factor authentication is applied based on the respective user's Microsoft settings. If 2FA is configured to be mandatory in your Microsoft environment, users will be automatically prompted to use 2FA during the Microsoft authentication process. No separate configuration is required in Flexopus.