This documentation applies to customers using Microsoft Entra ID as their identity provider (IdP) and the Security Assertion Markup Language (SAML) protocol for single sign-on (SSO).
Note: You do not need to import or manually create users in Learn before SSO is enabled. User accounts will be automatically provisioned upon first login via SSO.
Step 1 – Create a New Enterprise Application
- In the Microsoft Entra Admin Centre, Navigate to Identity > Applications > Enterprise Applications
- Select New Application
Select Create your own application
- Enter an Application Name
- Select Integrate any other application you don’t find in the gallery (Non-gallery)
- Click Create
Step 2 – Configure Single Sign On
Select Set Up Single Sign-On
Choose SAML
- Select Edit under Basic SAML Configuration
Step 3 – Enter Evotix SAML Details
- Your Evotix Consultant will provide your:
- Entity ID
- Reply URL
- Enter both of those values
Click Save
Step 4 – Add the Required Additional Claim
- Go to Attributes and Claims
- Select Add New Claim
- Paste the Claim Name (URL) provided by your Evotix Consultant
- Configure the claim
Click Save
The Attributes and Claims Section should now display the additional claim.
Important Note: Learn Only Reads Additional Claims
Learn does not use the default NameID value; it reads the value from the Additional Claims section.
Therefore:
- A new claim must be added in Entra ID representing the Object ID (user.objectid)
- The attribute name of this claim must match the UID field configured by your Evotix Consultant in Learn
- In Learn, your Evotix consultant will update the UID field(s) to match the attribute name used in the SAML claim
This ensures that the following all align correctly:
- The unique identifier sent in the SAML response
- The UID field configured in Learn
- The identity link between systems
Step 5 – Provide Federation Metadata
- Navigate to the SAML Signing Certificate Section
- Copy the App Federation Metadata URL
Send this URL to your Evotix Consultant
Step 6 - Completion
Once your Evotix Consultant has completed the required steps, SSO will be enabled in your Evotix Learn site.