Skip to content
Open app

securityHow-to guide

Configure SSO with Microsoft ADFS

Add a relying party trust in Active Directory Federation Services, set the claim rules, and connect it to ScatterSpoke from Settings → SSO.

Microsoft Active Directory Federation Services (ADFS) shares identity information between trusted parties over SAML 2.0. Connecting it to ScatterSpoke lets people use your directory to sign in. Workspace membership and seat limits still apply.

  • SSO must be available on your plan — the add-on on Business, or included on Enterprise. See Single sign-on.
  • You need administrator access to the ADFS management console and to ScatterSpoke.

Go to Settings → SSO and select Enable SSO. Copy the two values from step 1 of the card:

  • Entity ID / Issuer — the relying party trust identifier
  • ACS / Callback URL — the relying party SAML 2.0 service URL

In the ADFS management tool, expand Trust Relationships → Relying Party Trusts and select Add Relying Party Trust. In the wizard:

PromptValue
Display nameScatterSpoke
ProfileADFS profile
CertificateDefault
Configure URLEnable support for the SAML 2.0 WebSSO protocol, then paste the ACS / Callback URL
Relying party trust identifierPaste the Entity ID / Issuer — select Add before continuing
Multi-factor authenticationApply your organization’s required authentication policy
Access policy / issuance authorization rulesPermit the users or groups who should use ScatterSpoke

Finish the wizard and close it. Wizard labels vary by Windows Server version. Keep the access and MFA policy your organization requires; see Microsoft’s authentication policy guide.

Right-click the new trust and select Edit Claim Rules. You need two rules.

Rule 1 — send the email address. Add a rule using the Send LDAP Attributes as Claims template. Name it something like Get EmailAddress. Set Attribute store to Active Directory, then map E-Mail-Addresses (LDAP attribute) to E-Mail Address (outgoing claim type).

Rule 2 — transform it into the name ID. Add a rule using the Transform an Incoming Claim template. Set Incoming claim type to E-Mail Address, Outgoing claim type to Name ID, and Outgoing name ID format to Email. Leave Pass through all claim values selected.

The second rule is what lets ScatterSpoke create accounts: it puts the directory user’s email into the SAML NameID, which is where the default field mapping looks.

In the ADFS management tool, go to Service → Certificates, right-click Token-signing, and choose View Certificate. On the Details tab select Copy to File, choose DER encoded binary X.509 (.CER), and save it.

ScatterSpoke needs the certificate in PEM format. Convert it with OpenSSL:

Terminal window
openssl x509 -inform der -in certificate.cer -out certificate.pem

Back on Settings → SSO, step 2 offers three routes:

  • Fetch from URL — point it at your ADFS federation metadata, typically https://adfs.example.com/FederationMetadata/2007-06/FederationMetadata.xml. It must be reachable from the public internet.
  • Upload metadata.xml — if you downloaded that file instead.
  • Or enter manually — for internal-only ADFS deployments. Paste the SSO URL (entry point), usually https://adfs.example.com/adfs/ls/, and the X509 certificate in PEM format from step 4.

Then set the mapping. With the claim rules above, ADFS sends the email as the NameID, so leave Name field and Email field at nameID and Name transform method on Extract from email. Leave Family name field empty unless you added a surname claim.

Select Save SSO Configuration.

The card now shows SSO is enabled · Active. Sign in from a private browser window with a directory account and confirm you are handed to ADFS and returned signed in.

Only then turn on Enforce SSO for all users. Enforcement disables password login for everyone except organization administrators, who keep it as a recovery path.

Confirm that the test account is allowed by the relying party’s access policy. Then compare the Entity ID and ACS URL, check that NameID contains an email address, and verify that the signing certificate is current.

If metadata cannot be fetched from a private ADFS server, use Upload metadata.xml or enter the values manually. Keep enforcement off until the test succeeds.

ADFS token-signing certificates expire and roll. When yours does, sign-in fails until ScatterSpoke has the new one: select Reconfigure on the SSO card and re-fetch the metadata or paste the new PEM certificate. Put the expiry date in a calendar — an expired signing certificate can interrupt sign-in.