Access control: SSO with SAML2 / ADFS
Linkurious Enterprise supports any SAML2 compatible provider as external authentication providers.
To set up Linkurious Enterprise authentication with a SAML2 provider, you need to obtain the following parameters from the provider:
url: The URL of the SAML2 endpoint of the identity provider (e.g."https://example.com/adfs/ls"`),
identityProviderCertificate: The certificate of the identity provider in PEM format (e.g.
groupAttribute(optional): The attribute in which the groups of the users is stored (e.g.
emailAttribute(optional): The attribute in which the email of the users is stored
groupAttribute is the attribute of the SAML response containing the array of groups a user belongs to.
emailAttribute is the attribute of the SAML response that should contain the email address if the
of the SAML response is not already an email.
access.saml2 configuration with any SAML2 provider:
"access":// [...]"saml2":"enabled": true"url": """identityProviderCertificate": "/Users/example/linkurious/saml.pem""groupAttribute": "Groups"
To complete the login process, you need to configure your identity provider
to return the SAML response to Linkurious Enterprise at the following URL:
In particular, ADFS (Active Directory Federation Services) is a SAML2 provider that offers Single-Sign-On towards an Active Directory service, see more on Microsoft documentation.
To set up Linkurious Enterprise authentication with ADFS, Linkurious Enterprise has to be configured as a Relying Party Trust in ADFS (see how to configure the ADFS on the Microsoft documentation).