Configure Microsoft Azure AD SSO settings
Last updated October 25th, 2023
Note
If you enable Azure AD as a sign-in method, you can’t use your Samsung account to sign in to Knox services.
On the Knox Admin Portal
- In the top-right corner, click your account icon > My account.
- On the Manage your Account page, click the SSO SETTINGS tab.
On the Microsoft Azure portal
Next, add the Samsung Knox and Business Services app:
-
Under Azure services, click Azure Active Directory.
-
In the left sidebar, click Enterprise Applications.
-
Select New application.
-
In the Browse Azure AD Gallery section, enter Samsung Knox and Business Services in the search box.
-
Select the Samsung Knox and Business Services app from the results and add it.
Then, assign users and groups to the Samsung Knox and Business Services app:
-
In the left sidebar, click Users and groups.
-
Click Add user/group.
-
On the Add Assignment screen, under Users and groups, click None Selected.
-
In the list of users and groups, search for and select the users and groups to assign to the app. Then, click Select.
Note
Selected users must have an Azure Active Directory account.
-
At the bottom of the screen, click Assign to allow the users to access the app.
On the Knox Admin Portal
Finally, follow the steps below to set up the Basic SAML configuration:
-
In the Azure portal, select the Samsung Knox and Business Services application page, navigate to the Manage section and select Single sign-on.
-
Select SAML as the single sign-on method.
-
Under Basic SAML Configuration, enter the SAML info from your Samsung Knox settings:
- For the Identifier (entity ID) field, enter https://www.samsungknox.com.
- For the Reply URL (assertion consumer service URL) field, enter https://central.samsungknox.com/ams/ad/saml/acs.
- For the Sign on URL field, enter https://account.samsung.com/.
-
Under SAML Signing Certificate, copy the App federation metadata URL.
-
Navigate back to your Samsung Knox account settings. Under App federation metadata URL, paste the value you copied in Step 4.
-
Click CONNECT TO SSO.
-
In the sign-in window that opens, enter your AD credentials.
Caution
Once you verify the connection, a warning popup appears. If you click Continue, you can no longer use your Samsung account credentials to sign in to Knox services.
Is this page helpful?