Please note: The instructions listed in this article are exclusively applicable to those who have had SAML Single Sign-On activated for their company by Aircall. To have SAML Single Sign-On activated for your company, please contact your Account Manager. Please note that, at this time, this functionality is only offered for a limited number of customers.
______________________________
Step 1: Create an Enterprise Application
- Open Azure Portal.
- From the navigation menu on the left-hand side, click on Enterprise applications
- Click on New Application
- Click on Create your own application
- Select the option “Integrate any other application you don’t find in the gallery (Non-Gallery)”
- On the Create your own application modal, enter a name for your app(e.g. acme-saml@aircall)
- Click on Create
Step 2: Configure SAML
- From the Enterprise applications menu, select your app(e.g. acme-saml@aircall)
- Click on Single sign-on from the menu on the left-hand side
- Edit Basic SAML Configuration
- Add Identifier (Entity ID) with
urn:amazon:cognito:sp:us-west-2_hZkGBmIsz
- Add Reply URL (Assertion Consumer Service URL) with
https://sso.aircall.io/saml2/idpresponse
- Click on Save
- Add Identifier (Entity ID) with
Step 3: Export Metadata
- On the same page, from the SAML Certificates section:
- Click on the Download button of Federation Metadata XML
- Or, right-click copy the URL of the Download button
For more information on SAML, please read more here or contact your Account Manager.
Troubleshooting
If you are receiving the error below when logging in, it indicates that the email address does not match between Aircall and Azure AD.
Please follow the steps below to ensure the email address matches in Azure AD:
- Go to the user's details in Azure AD and find userPrincipleName. If userPrincipleName is not the same as the email address in Aircall then proceed further
- Go to SAML connection
- Edit Attributes & Claims
- Click on claims/emailaddress, which is usually the first field, with value user.mail
- Update Source attribute with user.userprincipalname and Save
- Recreate the SAML connection on Aircall and try to log in again