Single Sign On with ADFS

 

For all new ADFS integrations please use this guide.

If you are using the ADFS 3.0+ relying party trust wizard, please refer to this guide.

Litmos integrates with all SAML 2.0 providers, including ADFS 2.0 and 3.0. Litmos is an IdP initiated SSO service provider, which means that an Identity Provider login page is required to sign users into the Litmos application.  

To configure ADFS with Litmos, please follow these steps: 

  1. Begin by adding Litmos as a relying party trust in ADFS: 
    1. 1.png
  2. In some cases ADFS will require that you add the three different variations of party identifiers, however, usually your ADFS SAML endpoint will suffice. Your ADFS SAML endpoint is the 3rd on the list with "?adfs=1" appended to the URL.
    2.png

  3. Next, please add a NameID rule so that NameID is passed to Litmos as the user's Email Address from your Active Directory.

    3_NameID_.png

  4. Litmos requires that FirstName, LastName and Email of the user to be mapped as well for the connection to authenticate successfully. Please ensure that the "Outgoing Claim Types" are typed exactly as they appear in the screenshot below: 

    4.png
  5. Please add your Litmos ADFS endpoint:

    3.png

  6. Lastly, please ensure that Litmos' relying party trust is using a SHA-1 algorithm for the certificate as SHA-256 is not compatible with Litmos as this time(4/15/2016)

This completes the configuration of Litmos in your ADFS server. Next, we will need to add a few items into your Litmos account's SAML settings to complete the integration. To proceed, please login to your Litmos account as an Account Owner and follow these steps: 

  1. Once signed in as an Account Owner to your Litmos account, click the "Account" tab to access your account settings page. 
  2. From your account settings page, please click the "Integrations" tab.
  3. Scroll down the integrations list and click the "SAML 2.0 (Single Sign On)" setting. 
  4. Here you can enter your IdP sign in URL as well as the Base 64 certificate generated from ADFS. 

    SAML-Settings.png

 

You can now test the integration by signing into Litmos from your IdP sign in page. Please ensure that the "Autogenerate Users" is checked if the user does not exist in Litmos. If the user does exist, please ensure that their FirstName, LastName, Email and UserName(this should also be their Email) matches what is stored in your Active Directory. 

Have more questions? Submit a request

1 Comments

  • 2
    Avatar
    Paul Moran

    I would also add that it's important to correctly get the X.509 certificate from ADFS.

    In ADFS, go to Service\Certicates. Click on the Token Signing certicate to view it. Select the Details table and click Install to File. Select Base-64 encoded X.509 (.CER). 

    View the file, and copy the certicate to the above Certicate field on the Litmos page.

    If I had followed this, I may have prevented the hassle it took to figure why my ADFS was failing to log into Litmos!

Article is closed for comments.