What this connector is for
Once SSO is enabled, your staff access your Luxapps instance with their Microsoft 365 / Entra ID account — with no separate Luxapps password. Your directory policies (MFA, conditional access, revocation, auditing) apply automatically, and an offboarding handled in Entra ID cuts off access to Luxapps right away.
The protocol used is SAML 2.0 (Service-Provider-initiated). Luxapps acts as the Service Provider, and your Entra ID tenant as the Identity Provider.
What we need from you
Two items to send us at the end of the procedure, by email to your Luxapps contact:
-
①
Tenant ID
The unique identifier of your Entra ID tenant (GUID format).
-
②
Application ID
The identifier of the Enterprise Application you will have created for Luxapps.
Step 1 — Retrieve the Tenant ID
- Sign in to the Azure portal: https://portal.azure.com.
- In the portal search bar, type
Tenant propertiesand open the matching entry. - Copy the value of the Tenant ID field. This is your first deliverable.
Step 2 — Create the Enterprise Application
- In the search bar, type
Enterprise applications. - Click New application, then Create your own application.
- Give the application a name (for example Luxapps SSO). Select the option "Integrate any other application you don't find in the gallery (Non-gallery)", then confirm.
- Once the application is created, open its Overview screen. Copy the value of the Application ID field. This is your second deliverable.
Step 3 — Disable required assignment
By default, only explicitly assigned people can sign in. We recommend disabling this restriction so that access control is handled by a dedicated group (see "Lifecycle").
- In the left-hand menu, open Properties.
- Switch the Assignment required? field to No.
- Click Save.
Step 4 — Configure Single Sign-On (SAML)
- In the left-hand menu, open Single sign-on.
- Choose the SAML method.
- Click Edit in the Basic SAML Configuration block, then fill in the five URLs below.
Replace {YourDomain} with your Luxapps URL (for example
https://your-domain.lu) and {ApplicationID} with the value
copied in step 2.
| Field | Value to enter |
|---|---|
| Identifier (Entity ID) | {YourDomain} |
| Reply URL | {YourDomain}/saml/acs/{ApplicationID} |
| Sign-on URL | {YourDomain}/saml/login |
| Relay State | {YourDomain}/saml/acs/{ApplicationID} |
| Logout URL | {YourDomain}/saml/logout |
Concrete example: for a domain https://fiduciaire-x.lu
and an Application ID 518b88aa-d461-4c31-94ac-bfc6d3bfc3ba, the Reply URL is
https://fiduciaire-x.lu/saml/acs/518b88aa-d461-4c31-94ac-bfc6d3bfc3ba.
Send the two items to your Luxapps contact: Tenant ID and Application ID. We configure your instance and notify you as soon as SSO is active (typically within 1 business day).
Lifecycle & best practices
- Access control. Create an Entra ID security group (for example Luxapps Users) and assign it to the application: only its members will be able to sign in.
- Multi-tenant. If your staff are spread across several tenants, get in touch: we handle multi-IdP setups on a case-by-case basis.
- Auditing. On the Luxapps side, every SSO sign-in is logged and exportable; on the Entra ID side, the Sign-in logs give you full traceability.
If you run into trouble
If a step does not go as described (different Azure labels, missing rights on the tenant side, a SAML error on first login), contact your Luxapps contact with a screenshot of the error. We take over via video call if needed.