Steps to configure SAML SSO for Sage HR
About Sage HR
Sage HR is a cloud-based HRM solution for streamlining HR processes through various features, including employee self-service, absence management, performance tracking, recruitment, and payroll. Sage HR enables HR teams to manage employee data, track attendance, provide real-time insights, and ensure compliance with required laws and regulations.
The following steps will help you enable SAML-based SSO to Sage HR from ManageEngine Identity360.
Prerequisites
- The MFA and SSO license for Identity360 is required to enable SSO for enterprise applications.
- Log in to Identity360 as an Admin or Super Admin, or as a Technician with a role that has Application Integration and Single Sign-on permissions.
- Navigate to Applications > Application Integration > Create New Application, and select Sage HR from the applications displayed.
Note: You can also find Sage HR from the search bar located at the top.
- Under the General Settings tab, enter the Application Name and Description.
- Under Choose Capabilities tab, choose SSO and click Continue.
General Settings of SSO configuration for Sage HR.
- Under Integration Settings, navigate to the Single Sign On tab and select SAML from the Method drop-down. Click Metadata Details.
- Copy the Login URL, Entity ID/Issuer URL, and SHA 1, which will be used during the SSO configuration in Sage HR.
Integration Settings of SAML-based SSO configuration for Sage HR.
Sage HR (service provider) configuration steps
- Log in to the Sage HR portal as an admin or as a user with admin privileges.
- Click the profile icon at the top-right corner, and select Settings.
Settings tab in the Sage HR admin portal.
- On the settings menu pane, navigate to Integrations > SAML.
SAML settings in the Sage HR portal.
- Under the SAML SSO section, paste the values copied during step seven of the prerequisites in the following fields:
- Entity ID/Issuer URL in the Entity ID field
- Login URL in the Authentication URL field
- SHA 1 in the Key fingerprint field
SAML SSO configuration in the Sage HR portal.
- Click Save.
Identity360 (identity provider) configuration steps
- Switch to Identity360's application configuration page.
- In the Sub Domain field, paste the subdomain name retrieved from your Sage HR URL. For instance, if the URL is saturn.sage.hr, then saturn is the subdomain name.
- Enter the Relay State parameter, if necessary.
Note: Relay State is an optional parameter used with an SAML message to remember where you were or to direct you to a specific page after logging in.
Integration Settings of Sage HR configuration for the SAML method.
- Click Save.
- To learn how to assign users or groups to one or more applications, refer to this page.
Your users should now be able to sign in to Sage HR through the Identity360 portal.
Steps to enable MFA for Sage HR
Setting up MFA for Sage HR using Identity360 involves the following steps:
- Set up one or more authenticators for identity verification when users attempt to log in to Sage HR. Identity360 supports various authenticators, including Google Authenticator, Zoho OneAuth, and email-based verification codes. Click here for steps to set up the different authenticators.
- Integrate Sage HR with Identity360 by configuring SSO using the steps listed here.
- Now, activate MFA for Sage HR by following the steps mentioned here.
How does MFA for applications work in Identity360?