We use SAML (Security Assertion Markup Language), a standard that permits Azure AD to safely pass authorization credentials to service providers like Rewatch.
Azure AD setup
These are instructions for setting up Rewatch SAML SSO with Azure AD.
Setup the Rewatch app in Azure AD
In the Azure AD portal, select
Enterprise applications
from the left-side nav.Next, select
All Applications
in the left side nav, and click theNew application
button above the application list.
Type
Rewatch
In the search boxSelect the Rewatch application from the results.
Click the
Create
button.
When the application finishes creating, click
Single sign-on
in the left-side nav. UnderSelect a single sign-on method
, select SAML.
If prompted to to
Save single sign-on setting
, clickYes
If prompted to test single sign-on, click
No, I'll test later
Click
Download
next toCertificate (Base64)
in theSAML Signing Certificate
box. You will need this to setup the SAML configuration in Rewatch.Copy the
Login URL
under theSet up Rewatch
box. You will need this to setup the SAML configuration in Rewatch.
Rewatch setup
In Rewatch's admin console, click on the Single sign-on & provisioning link in the sidebar. Then click the button to configure SAML.
Next, fill out the configuration form to enable SAML:
Target URL: use Azure AD's
Login URL
Certificate: use the contents of the Azure AD certificate you downloaded
Managed email domains: enter email domains that will redirect to Okta for sign in
Once enabled, you'll see a preview link that you can use for testing.
โ
Enforcement
If you'd like to enforce SAML for sign in, you'll need to first sign in using SAML, then edit your SAML configuration to select your preferred enforcement policy.
SCIM
While SAML will automatically update user information whenever they log in, you can additionally setup SCIM to automate deprovisioning and group membership updates immediately after you make these administrative changes. We currently do not support SCIM integration with Azure AD