Skip to main content

Microsoft Entra

To configure HostedScan as a Service Provider in Microsoft Entra ID, follow these steps:

  1. In Entra, create a new Enterprise application: Add an enterprise application.

  2. Configure Entra to sign both the SAML response and the assertions. On the application's Single sign-on page, in section 3 SAML Certificates, click Edit next to Token signing certificate, set Signing Option to Sign SAML response and assertion, and click Save.

Entra Single sign-on page, SAML Certificates section, with the Edit button for the token signing certificate highlighted
Entra SAML Signing Certificate panel with Signing Option set to Sign SAML response and assertion
  1. Download the Entra metadata: in the same SAML Certificates section, click Download next to Federation Metadata XML.
Entra SAML Certificates section with the Federation Metadata XML download link highlighted
  1. In HostedScan, open Settings → SAML SSO, enable SAML SSO, and under Load from Metadata choose the XML input type, paste the contents of the downloaded file, and click Load Metadata to populate the Identity Provider fields.
HostedScan SAML SSO settings with the Entra metadata XML pasted into the Load from Metadata box
  1. Get HostedScan's metadata file: copy the SAML Metadata URL shown below the Identity Provider fields (https://api.hostedscan.com/auth/saml/<your-id>/metadata), open it in a browser, and save the XML to a file (for example with Save As…).
HostedScan SAML SSO settings with the SAML Metadata URL highlighted
HostedScan SAML metadata XML open in a browser with Save As highlighted
  1. Back in Entra, on the application's Single sign-on page, click Upload metadata file, select the file you just saved, and click Add.
Entra Upload metadata file dialog
  1. Assign the people who should be able to sign in: on the application's Users and groups page, click Add user/group and add the users or groups. Users who are not assigned get an Entra error when they try to sign in.

  2. Finally, in HostedScan click Test configuration (optional) and then Save SAML Settings.

HostedScan SAML SSO settings with the Test configuration and Save SAML Settings buttons highlighted

Signing in from Microsoft My Apps

Once configured, the enterprise application appears as a HostedScan tile in the My Apps portal and the Microsoft 365 app launcher for every assigned user. Clicking the tile signs the user in to HostedScan directly (IdP-initiated SSO), with no need to start from the HostedScan login page.