Before you start
You need:- An OpenWork organization with the Enterprise SSO entitlement.
- Owner or admin access in that OpenWork organization.
- Admin access to a Microsoft Entra enterprise application.
- The final OpenWork auth origin, for example
https://app.openworklabs.com.
1. Create the Entra enterprise app
In the Microsoft Azure portal, open Microsoft Entra ID and create a new enterprise application for OpenWork. Choose SAML as the single sign-on method.2. Configure Basic SAML Configuration
In Entra, open Single sign-on and edit Basic SAML Configuration. Set:
The Entity ID must be the OpenWork auth origin. Do not use the Entra tenant
identifier,
https://sts.windows.net/<tenant-id>/, as the Entity ID.
OpenWork SAML connections are organization-scoped. If a user belongs to
multiple OpenWork organizations, the Entra app, ACS URL, and Sign-in URL select
which organization they are entering.
3. Configure SAML signing
Open SAML Certificates and edit the token signing certificate settings. Set:- Signing Option:
Sign SAML assertion - Signing Algorithm:
SHA-256
saml_error and Invalid SAML response.
After any certificate change, copy the active certificate again. Entra can
create or activate a new signing certificate while you are editing SAML
settings, and OpenWork must store the certificate that is currently active.
4. Copy Entra values into OpenWork
In OpenWork, open the organization dashboard, then SSO. Choose SAML and enter:
Save the SSO connection. OpenWork then shows the generated ACS URL. Copy that
ACS URL back into Entra’s Reply URL if it was not available before the first
save. Copy the OpenWork Sign-in URL into Entra’s Sign on URL so the
Entra tile can launch the same organization-scoped flow.