Before you start
You need:- An TEC-CoWork organization with the Enterprise SSO entitlement.
- Owner or admin access in that TEC-CoWork organization.
- Admin access to a Microsoft Entra enterprise application.
- The final TEC-CoWork auth origin, for example
https://cowork.te-consulting.at.
1. Create the Entra enterprise app
In the Microsoft Azure portal, open Microsoft Entra ID and create a new enterprise application for TEC-CoWork. Choose SAML as the single sign-on method.2. Configure Basic SAML Configuration
In Entra, open Single sign-on and edit Basic SAML Configuration. Set:
The Entity ID must be the TEC-CoWork auth origin. Do not use the Entra tenant
identifier,
https://sts.windows.net/<tenant-id>/, as the Entity ID.
TEC-CoWork SAML connections are organization-scoped. If a user belongs to
multiple TEC-CoWork organizations, the Entra app, ACS URL, and Sign-in URL select
which organization they are entering.
3. Configure SAML signing
Open SAML Certificates and edit the token signing certificate settings. Set:- Signing Option:
Sign SAML assertion - Signing Algorithm:
SHA-256
saml_error and Invalid SAML response.
After any certificate change, copy the active certificate again. Entra can
create or activate a new signing certificate while you are editing SAML
settings, and TEC-CoWork must store the certificate that is currently active.
4. Copy Entra values into TEC-CoWork
In TEC-CoWork, open the organization dashboard, then SSO. Choose SAML and enter:
Save the SSO connection. TEC-CoWork then shows the generated ACS URL. Copy that
ACS URL back into Entra’s Reply URL if it was not available before the first
save. Copy the TEC-CoWork Sign-in URL into Entra’s Sign on URL so the
Entra tile can launch the same organization-scoped flow.