Skip to content
English
  • There are no suggestions because the search field is empty.

IdeaScale Azure Active Directory Integration

How to integrate IdeaScale with Azure Active Directory

Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon Settings

What is Azure Active Directory Integration?
Azure Active Directory Integration is a Single Sign-On method that connects IdeaScale with an organization's Azure Active Directory (Azure AD), so Azure AD controls which members have access to IdeaScale and members can be signed on automatically using their existing Azure AD accounts.

Integrating IdeaScale with Azure Active Directory lets an organization control, from Azure AD, which members have access to IdeaScale, enables automatic sign-on for members using their existing Azure AD accounts, and allows accounts to be managed from a single central location, the Azure portal. Additional background on single sign-on integration between SaaS applications and Azure Active Directory is available directly from Microsoft: https://docs.microsoft.com/en-us/azure/active-directory/active-directory-appssoaccess-whatis.


Role Permissions

  1. Workspace Administrator: Configures the SAML-based Single Sign-On connection between Azure AD and IdeaScale from Single Signon Settings, and provisions IdeaScale member accounts to complete the link between Azure AD users and their IdeaScale counterparts.
  2. Member: Authenticates to IdeaScale automatically through Azure AD once assigned access to the IdeaScale application in the Azure portal, rather than logging in with separate IdeaScale credentials.


Prerequisites

Configuring Azure Active Directory Integration with IdeaScale requires the following:

  1. Azure AD Subscription: An active Azure Active Directory subscription.
  2. IdeaScale Single Sign-On-Enabled Subscription: An IdeaScale subscription with Single Sign-On enabled.

Note: Testing the steps in this article in a production environment is not recommended.

This article tests Azure AD Single Sign-On in a test environment using a test user named Myrtle Riggs, and covers two main building blocks: Adding IdeaScale from the Gallery, and Configuring and Testing Azure AD Single Sign-On.


Adding IdeaScale from the Gallery

Configuring the integration of IdeaScale into Azure AD requires adding IdeaScale from the gallery to the list of managed SaaS apps.

To add IdeaScale from the gallery:

  1. In the Azure portal, on the left navigation panel, select the Azure Active Directory icon.
    downloads.intercomcdn.comio83581821f9daa5b5150247d61fd59791tutorial_general_01 copy
  2. Navigate to Enterprise Applications, then go to All Applications.downloads.intercomcdn.comio83582045bf73f3665d6f40be37ba5f2dtutorial_general_02 copy
  3. Select the New Application button at the top of the dialog to add a new application.
  4. In the search box, type IdeaScale.downloads.intercomcdn.comio83582205789bf084f6c52f3a0c7096f4tutorial_ideascale_addfromgallery copy
  5. In the results panel, select IdeaScale, then select the Add button to add the application.

Configuring and testing Azure AD single sign-on

This section configures and tests Azure AD Single Sign-On with IdeaScale, based on a test user called Myrtle Riggs.

For Single Sign-On to work, Azure AD needs a link relationship between an Azure AD user and the corresponding IdeaScale user. In IdeaScale, the value of the user name in Azure AD is assigned as the value of the Username field to establish this link.

Configuring and testing Azure AD Single Sign-On with IdeaScale involves the following building blocks:

  1. Configuring Azure AD Single Sign-On: Enables Single Sign-On for members.
  2. Creating an Azure AD Test User: Tests Azure AD Single Sign-On with Myrtle Riggs.
  3. Creating an IdeaScale Test User: Creates a counterpart of Myrtle Riggs in IdeaScale, linked to the Azure AD representation of the user.
  4. Assigning the Azure AD Test User: Enables Myrtle Riggs to use Azure AD Single Sign-On.
  5. Testing Single Sign-On: Verifies whether the configuration works.

Configuring Azure AD Single Sign-On

This section enables Azure AD Single Sign-On in the Azure portal and configures Single Sign-On in the IdeaScale application.

To configure Azure AD Single Sign-On with IdeaScale:

  1. In the Azure portal, on the IdeaScale application integration page, select Single Sign-On.
    downloads.intercomcdn.comio83589727241f1b11381f938b4211a59etutorial_general_04 copy
  2. On the Single Sign-On dialog, select SAML-based Sign-on as the Mode to enable Single Sign-On.downloads.intercomcdn.comio83589867b8c36f32d9cbe82d305d9a1btutorial_ideascale_samlbase copy
  3. On the IdeaScale Domain and URLs section:downloads.intercomcdn.comio83589917ed20b27c0024cd1bba7654d3tutorial_ideascale_url copy

    a.  In the Sign-on URL textbox, enter a URL using the pattern: https://<companyname>.ideascale.com

    b. In the Identifier textbox, enter a URL using the same pattern: https://<companyname>.ideascale.com
  4. On the SAML Signing Certificate section, select Metadata XML and save the metadata file.downloads.intercomcdn.comio83590078f641a60839ebad145baa6553tutorial_ideascale_certificate copy
  5. Select the Save button.
  6. On the IdeaScale Configuration section, select Configure IdeaScale to open the Configure Sign-On window, and copy the Sign-Out URL and SAML Entity ID from the Quick Reference section.downloads.intercomcdn.comio83590822d9cf2bda59261f018080f07etutorial_ideascale_configure copy
  7. In a separate browser window, log in to the IdeaScale company site as a Workspace Administrator (TO BE VERIFIED — source specifies only "administrator").
  8. Go to Settings >> Security >> Authentication >> Single Signon Settings.security
  9. As Single-Signon Type, select SAML 2.0.Screenshot 2025-08-23 at 1 copy
  10. On the Single Signon Settings dialog:Screenshot 2025-08-24 at 11.51.12 AM

    a. In the SAML IdP Entity ID textbox, paste the value of the SAML Entity ID copied from the Azure portal.

    b. Paste the content of the downloaded metadata file from the Azure portal into the SAML IdP Metadata textbox.

    c. In the Logout Success URL textbox, paste the value of the Sign-Out URL copied from the Azure portal. d. Select Save Changes.
Note: A concise version of these configuration instructions can be read directly inside the Azure portal while setting up the app. After adding IdeaScale from the Enterprise Applications section, selecting the Single Sign-On tab and then the Configuration section at the bottom surfaces this embedded documentation. Additional detail on this embedded documentation feature is available directly from Microsoft: https://go.microsoft.com/fwlink/?linkid=845985.

Creating an Azure AD Test User

This section creates a test user in the Azure portal called Myrtle Riggs.

downloads.intercomcdn.comio209311296ea6d1334e3c39d2c4c5d69fdupload_11729642575118222025 copy

 

To create a test user in Azure AD:

  1. In the Azure portal, on the left navigation panel, select the Azure Active Directory icon.
    downloads.intercomcdn.comio83581821f9daa5b5150247d61fd59791tutorial_general_01 copy
  2. To display the list of users, go to Users and Groups and select All Users.downloads.intercomcdn.comio83591699d3b1735666e17c6c7e1d56d8create_aaduser_02 copy
  3. To open the User dialog, select Add at the top of the dialog.downloads.intercomcdn.comio83591878be73d8caa2ff5fc4f37d2739create_aaduser_03 copy
  4. On the User dialog page:
    downloads.intercomcdn.comio2093105627eb5809ac4e69c45dd5fb234create_aaduser_04 copy

    a. In the Name textbox, enter MyrtleRiggs.

    b. In the User Name textbox, enter the email address for Myrtle Riggs.

    c. Select Show Password and record the value of the Password.

    d. Select Create.

Creating an IdeaScale Test User

For Azure AD users to log in to IdeaScale, they must be provisioned into IdeaScale. Provisioning is a manual task in IdeaScale.

To configure user provisioning:

  1. Log in to the IdeaScale site as a Workspace Administrator.
  2. Go to Workspace Homepage >> Navigation Panel >> Members.
  3. Select Quick Add.
  4. In the Add New Member section:downloads.intercomcdn.comio37093872474e8fcb3a3ac7d48ead81745Add+New+members copy

    a. In the Email Addresses textbox, enter the email address of the Azure AD account to provision.

    b. Select Save Changes. 

See Exceptions below for account confirmation requirements.

Note: Other IdeaScale member-creation tools or APIs can also be used to provision Azure AD accounts, in place of Quick Add.

Assigning the Azure AD Test User

This section grants Myrtle Riggs access to IdeaScale, enabling her to use Azure AD Single Sign-On.

To assign Myrtle Riggs to IdeaScale:

  1. In the Azure portal, open the applications view, navigate to the directory view, go to Enterprise Applications, then select All Applications.downloads.intercomcdn.comio83592886e0bd0f09cba690ae450a622ftutorial_general_201 copy
  2. In the applications list, select IdeaScale.downloads.intercomcdn.comio83593018e554151cc53d863f389fba41tutorial_ideascale_app copy
  3. In the left menu, select Users and Groups.
    downloads.intercomcdn.comio83593362a85f2de156126762831061e2tutorial_general_202 copy
  4. Select the Add button, then select Users and Groups on the Add Assignment dialog.downloads.intercomcdn.comio83593397c6dd0a3d00c652e2680f4274tutorial_general_203 copy
  5. On the Users and Groups dialog, select Myrtle Riggs in the Users list.
  6. Select the Select button on the Users and Groups dialog.
  7. Select the Assign button on the Add Assignment dialog.

Testing Single Sign-On

This section tests the Azure AD Single Sign-On configuration using the Access Panel. Selecting the IdeaScale tile in the Access Panel signs the test user in automatically to the IdeaScale application, confirming the configuration is working correctly.


Exceptions

  1. Account Confirmation: An IdeaScale member account provisioned through Quick Add requires the invited person to confirm the account through a confirmation email before the account becomes active. See Creating an IdeaScale Test User above.

Frequently Asked Questions

What is Azure Active Directory Integration used for?

Integrating IdeaScale with Azure Active Directory lets an organization control which members have access to IdeaScale from Azure AD, enables automatic sign-on for members using their existing Azure AD accounts, and allows accounts to be managed from a single central location, the Azure portal.

What is required before configuring Azure Active Directory Integration?

An Azure AD subscription and an IdeaScale Single Sign-On-enabled subscription are required. Testing the configuration in a production environment is not recommended.

How is an Azure AD user linked to the corresponding IdeaScale user?

The value of the user name in Azure AD is assigned as the value of the Username field in IdeaScale, establishing the link relationship Single Sign-On requires.

Is a newly provisioned IdeaScale test user active immediately?

No. See Exceptions above — the invited person must confirm the account through a confirmation email before it becomes active.

Where can the Azure AD Single Sign-On configuration instructions be accessed directly within the Azure portal?

A concise version of the configuration instructions can be read inside the Azure portal after IdeaScale is added under Enterprise Applications, by selecting the Single Sign-On tab and then the Configuration section.


Related Articles

 

Last Updated: August 15, 2026