This doc will help you quickly walk through the steps to create an Azure Active Directory app and set up the SAML SSO configuration through the app to sign in inside Hippo Video.

Pre-requisite:

  • To activate SSO you need Hippo Video Enterprise plan

  • Admin users of Hippo Video and Azure Active Directory will have access to set up SSO

Before starting with the configuration, ensure that your SSO Configuration page is kept open inside Hippo Video.

Click on Settings from the left nav bar and then click on the SSO Configuration card. 

To configure SSO with Azure AD

  1. Open the Azure AD portal in a new tab and log in with your existing credentials.

  2. Click on Enterprise Applications below Azure Services.

  3. Click New Application from the top and then Create your own application from the top left. 

  1. Enter the name of your app on the right-side of the screen and click Create

  1. You’ll be directed to the Overview screen of your application.

  2. Click on Single sign-on from the left navbar below the Manage tab.

  3. You’ll be navigated to the Set up Single Sign-On with SAML screen.

Note: The Login and Azure AD Identifier URLs are mandatory to configure the application with Hippo Video.

  1. Below Set up (application name), click on Copy to Clipboard near Login URL.

  2. Then, navigate to Hippo Video - SSO Configuration page and paste it inside the Target URL.

  3. Again, navigate to the Azure AD portal and copy the Azure AD Identifier URL.

  4. Then, navigate to Hippo Video - SSO Configuration page and paste it inside the Issuer URL.

  5. Below the SAML Signing Certificate, click on Download near Certificate (Base64) to get the certificate. 

  6. Open the downloaded file with Notepad and copy the text that begins right after BEGIN CERTIFICATE … and right before END CERTIFICATE. 

  1. Again, navigate to Hippo Video - SSO Configuration page and paste it inside the X509 Certificate

  2. Enter Your IDP domain (Azure AD Portal domain ID) in the Hippo Video - SSO Configuration page upon which the ACS URL at the bottom of the page will be updated accordingly.
    Note: The ACS URL is mandatory to configure with Azure AD.

To set Basic SAML Configuration

  1. Navigate to the Azure AD portal.
    NoteIdentifier (Entity ID), and Reply URL (Assertion Consumer Service URL) are mandatory to set from Hippo Video. The Identifier (Entity ID) and Azure AD Identifier both are the same.

  1. Copy the Azure AD Identifier below the Set up (application nameand then click on Edit near Identifier (Entity ID).

  2. Paste it inside the Identifier (Entity ID)

  1. Navigate to Hippo Video - SSO Configuration page and copy the ACS URL.

  2. Again, navigate to the Azure AD portal and paste it inside the Reply URL

  1. Enter the Sign on URL i.e. ACS URL. Here, edit the URL by removing the text ‘/callback’ to ensure the valid URL.

Note: This is the URL from which the authentication request originates.

  1. Click Save

To set User Attributes & Claims

  1. Ensure that the Unique User Identifier is set as ‘user.mail’. Click Edit.
    Note: This unique ID helps in identifying the user inside Hippo Video

  1. Double-click on the ‘user.mail’.

  2. Ensure that the Name Identifier Format is selected as Email Address and then click Save.

To set/add users inside Azure AD

  • Click on Users and Groups from the left navbar, to set or add users who have an access to login Hippo Video using SSO.

Now, you have successfully done the configuration process inside Azure AD

To complete the configuration process inside Hippo Video 

  1. Navigate to Hippo Video - SSO Configuration page and check for the details filled.

  2. Then click Save to complete the configuration process.