Note: If you use Azure AD as your Identity Provider, we have step-by-step instructions for setting up your SAML connection found here. ADFS instructions found here.
Bentley's Service Provider Details (configure your server with this info)
Note: It is required that a user have a valid country code in your directory in order to federate. We use this information to determine proper entitlements, billing, taxes, and more.
Assertion Consumer URL
Assertion validity duration
Include Name ID in assertion
Attributes to include in assertion
emailaddress OR upn (depending on your identifier)
country (2-digit ISO code)
Namespace for attributes to include in assertion
Your SAML 2.0 Identity Provider Information (send this info back to Bentley)
e.g. bentley.com <This is used to redirect users to your IdP if IMS sees this during the authentication process>
Entity ID in the Federation Metadata document if you have one.
Typically for ADFS it looks something like:http://<ADFS>/adfs/ly/FederationMetadata/2007-06/FederationMetadata.xml
Entity Metadata URL*
Federation Metadata document if your IdP exposes it.
SSO Service URL
URL where your users will be redirected to, for authentication by your IdP.
Typically for ADFS it looks like: https://<ADFS>/adfs/ls
The thumbprint of the certificate used by your IdP for token signing