Before you start
You need:- An OpenWork organization with the Enterprise SSO entitlement.
- Owner or admin access in that OpenWork organization.
- Admin access to a Microsoft Entra enterprise application.
- The final OpenWork auth origin, for example
https://app.openworklabs.com.
1. Create the Entra enterprise app
In the Microsoft Azure portal, open Microsoft Entra ID and create a new enterprise application for OpenWork. Choose SAML as the single sign-on method.2. Configure Basic SAML Configuration
In Entra, open Single sign-on and edit Basic SAML Configuration. Set:
The Entity ID must be the OpenWork auth origin. Do not use the Entra tenant
identifier,
https://sts.windows.net/<tenant-id>/, as the Entity ID.
OpenWork SAML connections are organization-scoped. If a user belongs to
multiple OpenWork organizations, the Entra app, ACS URL, and Sign-in URL select
which organization they are entering.
3. Configure SAML signing
Open SAML Certificates and edit the token signing certificate settings. Set:- Signing Option:
Sign SAML assertion - Signing Algorithm:
SHA-256
saml_error and Invalid SAML response.
After any certificate change, copy the active certificate again. Entra can
create or activate a new signing certificate while you are editing SAML
settings, and OpenWork must store the certificate that is currently active.
4. Copy Entra values into OpenWork
In OpenWork, open the organization dashboard, then SSO. Choose SAML and enter:
Save the SSO connection. OpenWork then shows setup values including
Sign-in URL, Redirect URL, ACS URL, and Metadata URL. Copy the
generated ACS URL back into Entra’s Reply URL if it was not available
before the first save. Copy the OpenWork Sign-in URL into Entra’s
Sign on URL so the Entra tile can launch the same organization-scoped flow.
The saved configuration is still disabled at this point.
5. Verify the email domain
In OpenWork Settings → SSO, select Request token under domain verification. Create a DNS TXT record for the email domain:
Use the host value when your DNS provider appends the domain automatically. Use
the full DNS name when your provider expects the complete record name. After the
TXT record resolves publicly, select Verify domain in OpenWork.
The token is a one-time proof and expires after seven days. After verification
succeeds, you may remove the TXT record.
6. Assign test users
In Entra, open the enterprise application’s Users and groups page and assign the users who should be allowed to sign in. For external users, assign the guest identity shown by Entra, not only the original external email address.7. Test and enable SSO in OpenWork
After the Entra assignment and domain verification are complete:- In OpenWork Settings → SSO, select Enable Config or Enable SSO.
- In the Test SSO before enabling it dialog, select SSO Login.
- Complete Microsoft authentication in the separate window.
- Return to OpenWork and confirm Authentication test successful.
- Select Enable SSO.
Just-in-time provisioning and password signup
After Entra SAML SSO is enabled for a verified domain, OpenWork’s standard sign-in flow routes users with that email domain to the organization SSO flow. When a user completes SAML sign-in successfully, OpenWork can create their organization membership just in time with the defaultMember role.
JIT provisioning happens only after successful SAML authentication. Creating an
email/password account with the same email domain does not add the user to the
organization or create a SCIM-managed identity. If that user later completes
SSO, OpenWork can link the matching account and provision the organization
membership through SSO.
OpenWork does not convert SAML attributes such as role, groups, or admin
into elevated organization roles. Assign Admin, Owner, or custom roles in
OpenWork after review, or through an invitation that grants the intended role.