Search Results :

×

Guide to Configure Umbraco SAML SSO using Azure B2C as IDP

Umbraco SAML Single Sign-On (SSO) plugin gives the ability to enable SAML Single Sign-On for your Umbraco applications. Using Single Sign-On you can use only one password to access your Umbraco application and services. Our plugin is compatible with all the SAML compliant Identity providers. Here we will go through a step-by-step guide to configure Single Sign-On (SSO) between Umbraco and Azure B2C considering Azure B2C as IdP.

Select your umbraco version to configure SSO with:
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco8.SAML.SSO -Version 5.4.2

> dotnet add package miniOrange.Umbraco8.SAML.SSO --version 5.4.2

  • Add miniorange-saml-sso.dll in the bin folder (where your other DLL files exist) for your Umbraco site.
  • Register miniorangesamlsso module for your umbraco SSO according to the provided steps in the integration.md file.
  • Add the provided configuration file saml.config in the root directory for your umbraco site.
  • Run the application when the configuration is done.
  • Download Umbraco SAML Single Sign-On (SSO) module.
  • For Setting up the module, extract the umbraco-saml-sso-connector.zip, you will find a DLL file miniorange-saml-sso.dll, a configuration file saml.config and a integration.md file which contain the steps for adding the module into your application.
  • Add miniorange-saml-sso.dll in the bin folder (where your other DLL files exist) for your Umbraco site.
  • Register miniorangesamlsso module for your umbraco SSO according to the provided steps in the integration.md file.
  • Add the provided configuration file saml.config in the root directory for your umbraco site.
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco8.SAML.SSO -Version 5.4.2

> dotnet add package miniOrange.Umbraco8.SAML.SSO --version 5.4.2

  • Add miniorange-saml-sso.dll in the bin folder (where your other DLL files exist) for your Umbraco site.
  • Register miniorangesamlsso module for your umbraco SSO according to the provided steps in the integration.md file.
  • Add the provided configuration file saml.config in the root directory for your umbraco site.
  • Run the application when the configuration is done.
  • Download Umbraco SAML Single Sign-On (SSO) module.
  • For Setting up the module, extract the umbraco-saml-sso-connector.zip, you will find a DLL file miniorange-saml-sso.dll, a configuration file saml.config and a integration.md file which contain the steps for adding the module into your application.
  • Add miniorange-saml-sso.dll in the bin folder (where your other DLL files exist) for your Umbraco site.
  • Register miniorangesamlsso module for your umbraco SSO according to the provided steps in the integration.md file.
  • Add the provided configuration file saml.config in the root directory for your umbraco site.
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 9.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 9.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your startup.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the startup.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;

  namespace Application
  {
    public class Startup
    {

      // Add services to the container.
      public void ConfigureServices(IServiceCollection services)
      {
        services.AddUmbraco(_env, _config)
          .AddBackOffice()
          .AddWebsite()
          .AddComposers()
          .Build();

        services.AddminiOrangeServices(Assembly.GetExecutingAssembly());
      }

      public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
      {
        if (env.IsDevelopment())
        {
          app.UseDeveloperExceptionPage();
        }
        app.UseUmbraco()
          .WithMiddleware(u =>
          {
            u.UseBackOffice();
            u.UseWebsite();
            u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
          })
          .WithEndpoints(u =>
          {
            u.UseInstallerEndpoints();
            u.UseBackOfficeEndpoints();
            u.UseWebsiteEndpoints();
          });
      }
    }
  }
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 10.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 10.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your startup.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the startup.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;

  namespace Application
  {
    public class Startup
    {

      // Add services to the container.
      public void ConfigureServices(IServiceCollection services)
      {
        services.AddUmbraco(_env, _config)
          .AddBackOffice()
          .AddWebsite()
          .AddComposers()
          .Build();

        services.AddminiOrangeServices(Assembly.GetExecutingAssembly());
      }

      public void Configure(IApplicationBuilder app, IWebHostEnvironment env)
      {
        if (env.IsDevelopment())
        {
          app.UseDeveloperExceptionPage();
        }
        app.UseUmbraco()
          .WithMiddleware(u =>
          {
            u.UseBackOffice();
            u.UseWebsite();
            u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
          })
          .WithEndpoints(u =>
          {
            u.UseInstallerEndpoints();
            u.UseBackOfficeEndpoints();
            u.UseWebsiteEndpoints();
          });
      }
    }
  }
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 11.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 11.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 12.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 12.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 13.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 13.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 14.2.3

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 14.2.3

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 15.2.4

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 15.2.4

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 16.2.4

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 16.2.4

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 17.2.4

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 17.2.4

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.
NuGet Package
.NET CLI

PM> NuGet\Install-Package miniOrange.Umbraco.SAML.SSO.Login -Version 18.0.0

> dotnet add package miniOrange.Umbraco.SAML.SSO.Login --version 18.0.0

  • Download Umbraco SAML Single Sign-On (SSO) middleware.
  • For Setting up the middleware, you will be required to add the below namespaces, services and middleware in your program.cs file (marked in green), below here is a sample example.
    Include only the highlighted section below in the program.cs file of your application.
  using miniOrange.saml;
  using System.Reflection;
  WebApplicationBuilder builder = WebApplication.CreateBuilder(args);

  builder.CreateUmbracoBuilder()
    .AddBackOffice()
    .AddWebsite()
    .AddDeliveryApi()
    .AddComposers()
    .Build();

  // Add services to the container.
  builder.Services.AddminiOrangeServices(Assembly.GetExecutingAssembly());

  WebApplication app = builder.Build();

  await app.BootUmbracoAsync();

  app.UseUmbraco()
    .WithMiddleware(u =>
    {
      u.UseBackOffice();
      u.UseWebsite();
      u.AppBuilder.UseminiOrangeSAMLSSOMiddleware();
    })
    .WithEndpoints(u =>
    {
      u.UseBackOfficeEndpoints();
      u.UseWebsiteEndpoints();
    });
  await app.RunAsync();
  • Run the application when the configuration is done.

Step by Step guide for Umbraco SAML SSO using Azure B2C as Identity Provider.

  • After integration, open your browser and browse the connector dashboard with the URL below:
 https://<umbraco-base-url>/?ssoaction=config
  • If the registration page or login page pops up, you have successfully added the miniOrange SAML SSO middleware in your application.
Umbraco SAML SSO - registration page

  • Register or log in with your account by clicking the Register button to configure the middleware.
  • After successful registration, you will receive a trial license key on your registered email address.
  • To activate the middleware, you can either:
    • Enter the license key received via email in the provided input field.

    OR

    • Upload the license file that you downloaded by clicking on the Click Here button.
Umbraco SAML SSO - Verify Trial License

  • Then, check the box "I have read the above conditions and I want to activate the middleware", and click the Activate License button.
Umbraco SAML SSO - Activate License

There are two ways detailed below with which you can get the SAML SP metadata to configure onto your Identity Provider end.

A] Using SAML metadata URL or metadata file
  • In the Plugin Settings menu, look for Service Provider Settings. Under that, you can find the metadata URL as well as the option to download the SAML metadata.
  • Copy metadata URL or download the metadata file to configure the same on your identity provider end.
  • You may refer to the screenshot below:
Umbraco SAML SSO - Service Provider Metadata

B] Uploading metadata manually
  • From the Service Provider Settings section, you can manually copy the service provider metadata like SP Entity ID, ACS URL, Single Logout URL and share it with your identity provider for configuration.
  • You may refer to the screenshot below:
Umbraco SAML SSO - enter SP metadata manually

Register the Identity Experience Framework application

  • Log into Azure B2C Portal.
  • From the Azure AD B2C tenant, select App registrations, and then select New registration.
Azure B2C Portal

  • For Name, enter IdentityExperienceFramework.
  • Under Supported account types, select Accounts in this organizational directory only.
Supported account types

  • Under Redirect URI, select Web, and then enter "https://your-tenant-name.b2clogin.com/your-tenant-name.onmicrosoft.com", where your-tenant-name is your Azure AD B2C tenant domain name.

Note: In the following step if the 'Permissions' section is not visible then it might be the reason that you don't have an active AzureAD B2C subscription for that tenant. You can find the details regarding the AzureAD B2C subscription here and you can create a new tenant by following the steps here.


  • Under Permissions, select the Grant admin consent to openid and offline_access permissions check box.
  • Click on Register.
Redirect URI

  • Record the Application (client) ID for use in a later step.
Application (client) ID

Register the Identity Experience Framework application

  • Under Manage, select Expose an API.
  • Select Add a scope, then select Save and continue to accept the default application ID URI.
Identity Experience Framework application

  • Enter the following values to create a scope that allows custom policy execution in your Azure AD B2C tenant:
    • Scope name: user_impersonation
    • Admin consent display name: Access IdentityExperienceFramework
    • Admin consent description: Allow the application to access IdentityExperienceFramework on behalf of the signed-in user.
  • Select Add scope.
Custom policy execution

Register the ProxyIdentityExperienceFramework application

  • Select App registrations, and then select New registration.
  • For Name, enter ProxyIdentityExperienceFramework.
  • Under Supported account types, select Accounts in this organizational directory only.
ProxyIdentityExperienceFramework application

  • Under Redirect URI, use the drop-down to select Public client/native (mobile & desktop).
  • For Redirect URI, enter myapp://auth.
  • Under Permissions, select the Grant admin consent to openid and offline_access permissions check box.
  • Select Register.
ProxyIdentityExperienceFramework application

  • Record the Application (client) ID for use in a later step.
ProxyIdentityExperienceFramework application

Next, specify that the application should be treated as a public client

  • Under Manage, select Authentication.
  • Under Advanced settings, enable Allow public client flows (select Yes).
  • Select Save.
Allow public client flows

Now, grant permissions to the API scope you exposed earlier in the IdentityExperienceFramework registration

  • Under Manage, select API permissions.
  • Under Configured permissions, select Add a permission.
IdentityExperienceFramework registration

  • Select the My APIs tab, then select the IdentityExperienceFramework application.
IdentityExperienceFramework registration

  • Under Permission, select the user_impersonation scope that you defined earlier.
  • Select Add permissions. As directed, wait a few minutes before proceeding to the next step.
IdentityExperienceFramework registration

  • Select Grant admin consent for (your tenant name).
IdentityExperienceFramework registration

  • Select your currently signed-in administrator account, or sign in with an account in your Azure AD B2C tenant that's been assigned at least the Cloud application administrator role.
  • Select Yes.
  • Select Refresh, and then verify that "Granted for ..." appears under Status for the scopes - offline_access, openid and user_impersonation. It might take a few minutes for the permissions to propagate.
IdentityExperienceFramework registration

Register the Umbraco Application

  • Select App registrations, and then select New registration.
  • Enter a Name for the application such as: WP-app.
  • Under Supported account types, select Accounts in any organizational directory or any identity provider. For authenticating users with Azure AD B2C.
Register the Umbraco Application

  • Under Redirect URI, select Web, and then enter the ACS URL from the Service Provider Settings tab of the miniOrange Umbraco SAML plugin, as mentioned in Step 2B above.
  • Select Register.
Register the Umbraco Application

  • Under Manage, click on Expose an API.
  • Click on Set for the Application ID URI and then click on Save, accepting the default value.
Register the Umbraco Application

  • Once saved, copy the Application ID URI and navigate to the Service Provider Metadata tab of the plugin.
  • Paste the copied value under the SP Entity ID / Issuer field provided in this tab.
  • Click on Save.

Generate SSO Policies

  • From our Azure B2C portal, navigate to the Overview section of your B2C tenant and record your tenant name.
    NOTE: If your B2C domain is b2ctest.onmicrosoft.com, then your tenant name is b2ctest.
Generate SSO Policies

  • Enter your Azure B2C tenant name below, along with the application ID for IdentityExperienceFramework and ProxyIdentityExperienceFramework apps as registered in the above steps.
Azure B2C tenant Name:
IdentityExperienceFramework app ID:
ProxyIdentityExperienceFramework app ID:
Select additional attributes

  • Click on the Generate Azure B2C Policies button to download the SSO policies.
  • Extract the downloaded zip file. It contains the policy files and certificate (.pfx), which you will require in the following steps.

Setup and upload Certificates

Note: In the following step if the 'Identity Experience Framework' is not clickable then it might be the reason that you don't have an active Azure AD B2C subscription for that tenant. You can find the details regarding the Azure AD B2C subscription here and you can create a new tenant by following the steps here.


  • Sign in to the Azure portal and browse to your Azure AD B2C tenant.
Setup and upload Certificates

  • Under Policies, select Identity Experience Framework and then Policy keys.
Identity Experience Framework

  • Select Add, and then select Options > Upload.
  • Enter the Name as SamlIdpCert. The prefix B2C_1A_ is automatically added to the name of your key.
Create a Key

  • Using the upload file control, upload your certificate that was generated in the above steps along with the SSO policies (tenantname-cert.pfx).
  • Enter the certificate's password as your tenant name and click on Create. For example, if your tenant name is xyzb2c.onmicrosoft.com, enter the password as xyzb2c.
  • You should be able to see a new policy key with the name B2C_1A_SamlIdpCert.

Create the signing key

  • On the overview page of your Azure AD B2C tenant, under Policies, select Identity Experience Framework.
  • Select Policy Keys and then select Add.
  • For Options, choose Generate.
  • In Name, enter TokenSigningKeyContainer.
  • For Key type, select RSA.
  • For Key usage, select Signature.
Create the signing key

  • Select Create.

Create the encryption key

  • On the overview page of your Azure AD B2C tenant, under Policies, select Identity Experience Framework.
  • Select Policy Keys and then select Add.
  • For Options, choose Generate.
  • In Name, enter TokenEncryptionKeyContainer.
  • For Key type, select RSA.
  • For Key usage, select Encryption.
Create the encryption key

  • Select Create.

Upload the policies

  • Select the Identity Experience Framework menu item in your B2C tenant in the Azure portal.
Upload the policies

  • Select Upload custom policy.
Upload the policies

  • As per the following order, upload the policy files downloaded in the above steps:
    • TrustFrameworkBase.xml
    • TrustFrameworkExtensions.xml
    • SignUpOrSignin.xml
    • ProfileEdit.xml
    • PasswordReset.xml
    • SignUpOrSigninSAML.xml
  • As you upload the files, Azure adds the prefix B2C_1A_ to each.

You have successfully configured Azure B2C as SAML IDP (Identity Provider) for achieving Umbraco Single Sign-On (SSO).

  • Click on the Add new IDP button to configure a new Identity Provider.
Umbraco SAML SSO using Azure B2C as IDP - Add New IDP

  • Under the Plugin Settings tab, select Azure B2C as your identity provider from the list shown.
Umbraco SAML SSO using Azure B2C as IDP - Select Azure B2C

There are two ways detailed below with which you can configure your SAML Identity Provider metadata in the middleware.

A] Upload metadata using the Upload IDP Metadata button:
  • If your identity provider has provided you with the metadata URL or metadata file (.xml format only), then you can simply configure the identity provider metadata in the middleware using the Upload IDP Metadata option.
  • Copy metadata URL or download the metadata file to configure the same on your identity provider end.
  • You may refer to the screenshot below:
Umbraco SAML SSO - Upload IDP Metadata

  • You can choose any one of the options according to the metadata format you have available.
B] Configure the identity provider metadata manually:
  • After configuring your Identity Provider, it will provide you with IDP Entity ID, IDP Single Sign On URL and SAML X509 Certificate fields respectively.
  • Click Save to save your IDP details.
Umbraco SAML SSO - Configure IDP Manually

  • After uploading the metadata details, navigate to the Identity Provider Settings section. Hover over the Select Actions dropdown and click on Test Configuration.
Umbraco SAML SSO - Test Configuration

  • The screenshot below shows a successful result. Click on SSO Integration to further continue with the SSO Integration.
Umbraco SAML SSO - Test Configuration Successful

  • If you are experiencing any error on the middleware end you’ll be shown with the window similar to below.
Umbraco SAML SSO - Test Configuration Error

  • To troubleshoot the error you can follow the below steps:
  • Under Troubleshoot tab, enable the toggle to receive the plugin logs.
Umbraco SAML SSO - TroubleShoot

  • Once enabled, you will be able to retrieve plugin logs by navigating to Plugin Settings tab and clicking on Test Configuration.
  • Download the log file from the Troubleshoot tab to see what went wrong.
Umbraco Login Type
  • After this, select the Login Type from the dropdown on the right side of the Identity Provider Settings page.
  • You can choose from BackOffice, Member, or Custom Attribute based.
  • Note: The Custom Attribute based login type is available in the Premium and Enterprise versions.
Umbraco SAML SSO - Umbraco Login Type
  • Attribute Mapping, Role Mapping and Domain Restriction are available in the Premium and Enterprise versions of the middleware.
Umbraco SAML SSO - Attribute Mapping

  • Hover on Select Actions and click on Copy SSO Link.
Umbraco SAML SSO - Copy SSO Link

  • Use the following URL as a link in the application from where you want to perform SSO:
  https://<umbraco-base-url>/?ssoaction=login
  • For example, you can use it as:
  <a href="https://<umbraco-base-url>/?ssoaction=login">Log in</a>
  • Use the following URL as a link to your application from where you want to perform SLO:
  https://<umbraco-base-url>/?ssoaction=logout
  • For example, you can use it as:
  <a href="https://<umbraco-base-url>/?ssoaction=logout">Log out</a>

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

We'll Reach Out to You at the Earliest!


ADFS_sso ×
Hello there!

Need Help? We are right here!

support