These instructions explain how to create a new enterprise application in Azure Active Directory and configure Single Sign-On (SSO) for AirMaestro using SAML.
In this guide:
Create a new enterprise application
Configure SAML settings
Configure user attributes and claims
Send configuration details to the Ops & Safety Suite Team
Assign users and groups
Before you begin
You will need:
- Access to Entra AD Active Directory with permission to create Enterprise Applications
- Your AirMaestro site URL
Step 1. Create the Enterprise Application
- In Entra Active Directory, go to Enterprise applications and click New application.
- Switch to the legacy app gallery.
- Select Non-gallery application.
- Enter a name for the application, such as “AirMaestro”, then click Add.
Step 2. Configure SAML settings
- Open the newly created application and select Single sign-on.
- Select SAML as the sign-on method.
- Under Basic SAML Configuration, click Edit.
- Configure the following fields:
-
Identifier (Entity ID)
- Remove the default generated URL.
- Enter your AirMaestro site URL.
-
Example:
https://your-site.airmaestro.com.au/
-
Reply URL (Assertion Consumer Service URL)
-
Enter your AirMaestro site URL followed by:
/SingleSignOn.ashx
-
Example:
https://your-site.airmaestro.com.au/SingleSignOn.ashx
-
-
Sign on URL
- Leave blank.
- Leave blank.
-
Relay State
- Leave blank.
- Leave blank.
-
Logout URL
- Leave blank.
- Leave blank.
- Click Save.
Step 3. Configure User Attributes and Claims
- Under User Attributes & Claims, click Edit.
- Update the attributes as required.
The most important field is the Unique User Identifier, as this is used to match users between Entra AD and AirMaestro.
Depending on your Entra AD configuration, this is commonly set to:
user.userprincipalnameuser.mailuser.onpremisessamaccountname
In AirMaestro, the Unique User Identifier is matched against the Personnel record’s Single Sign-On NameID field.
Step 4. Send Configuration Details to Ops and Safety Suite Team
- Copy the App Federation Metadata URL.
- Send the following information to the Ops & Safety Suite Support Team (support@velloxgroup.com):
- Your configured Entity ID
- Your App Federation Metadata URL
Our team will complete the AirMaestro-side configuration and notify you once setup is complete.
Step 5. Assign Users and Groups
- In the application, select Users and groups.
- Assign the application to the required users and groups.
Additional Notes
- Users must have a valid value configured in the AirMaestro Single Sign-On NameID field.
- The value configured in Entra AD for the Unique User Identifier must match the corresponding AirMaestro user record.
- If the identifiers do not match, users may be unable to sign in using SSO.
Comments
0 comments
Please sign in to leave a comment.