Configure Azure SAML Single Sign-On (SSO)
Setting up your Corporategift.com SSO account? You can use Microsoft Azure as the identity provider (IdP) for your enterprise users to sign in to corporategift.com via SSO with their Microsoft account
Setting up your Corporategift.com SSO account?
You can use Microsoft Azure as the identity provider (IdP) for your enterprise users to sign in to corporategift.com via SSO with their Microsoft username and password.
Single Sign-On (SSO) brings the most secure access to Corporategift.com without the need of the corporategift sign in process, and authenticating with your enterprise's Azure account.
Every time you access Corporategift.com as an SSO user, it automatically reroutes you securely to Azure, and then after authentication, it routes you back to your corporategift.com account as a signed in user.
SSO uses the secure SAML 2.0 protocol to delegate the entire authentication process to Azure.
Prerequisites:
To configure SSO, you need:
- Administrator or Super Admin access to your CorporateGift account
- An Azure account with an active subscription.
- One of the following roles: Global Administrator, Cloud Application Administrator, Application Administrator, or owner of the service principal.
- Completion of the steps in Quickstart: Create and assign a user account.
CorporateGift now supports self-service SSO configuration. Once you've completed the Azure setup, simply copy the required values back into CorporateGift - no support ticket is required.
Step 1 – Open the SSO Integration
- In CorporateGift, navigate to My Integrations.
- Select the SSO tab.
- Click Add on the Azure integration.
You will now see the SSO Configuration screen.
Step 2 – Configure Authentication
Choose how users should authenticate.
Allow only SSO login
Enable this option if you want users to sign in exclusively through Azure.
Users will no longer be able to log in using their CorporateGift password.
Allow to create new users with SSO
Enable this option if you want CorporateGift to automatically create user accounts when someone signs in through Azure for the first time.
If this option is disabled, every user must already exist in CorporateGift before they can sign in.
Users can be created by:
- HRIS integrations
- Manual user creation
- CSV import
Step 3 – Choose Your Company Name
Enter a CompanyName.
Important
This value:
- must be lowercase
- cannot contain spaces
- should remain permanent
Example:
acme
CorporateGift automatically generates:
- Reply URL (Assertion Consumer Service URL)
- Identifier (Entity ID)
These values will be used when configuring your Azure application, so they must match exactly.
Step 4 – Configure the Azure SAML Application
Enable single sign-on:
- You need to login at: https://portal.azure.com/
- Go to Enterprise applications.

- Click New application.

- Click Create your own application.

- Enter the SAML application details:
- Application name: "Corporategift".
- Choose “Integrate any other application you dont find in the gallery (Non-gallery)".
- Click Create

- You will be redirected to the Corporategift application main page. You will now need to click Single-sign on.

- In the next screen choose SAML method

- Next we need to go through the setup SAML steps, Click Edit on the "Basic SAML Configuration" step:

- Get the Identifier (Entity ID) field and the the Reply URL:
- login to your corporategift.com account (you must be an account owner or a super admin), and navigate to the my integrations section: https://account.corporategift.com/my-integrations/
- Click on the SSO tab, select Microsoft Azure and click "Add"
- enter you company name in the company name field remove spaces and kip and convert all letters to lowercase
- copy the the Identifier (Entity ID) field and the the Reply URL

- Fill the configuration details as bellow:
-
- In Identifier (Entity ID) field add the identifier url you copied in the previous step :
make sure it matches what you see in the SSO settings on corporategift (should end with "metadata" - Remove this first auto added option. (the one starting with "http://asapplicationregistery...")
- In the Reply URL section add the Reply URL you copied in the previous step :
make sure it matches what you see in the SSO settings on corporategift (should end with "acs"
- Save.
- In Identifier (Entity ID) field add the identifier url you copied in the previous step :
- Now we need to edit the User Attributes & Claims section:
- Click Edit:

- Click on Unique User Identifier

- Change the "Name identifier format" to Default and the "Source attribute" to user.userprincipalname.

- Save it.
- Next we will make some more changes to the Additional claims section:
- Delete rows data:
- emailaddress
- givenname
.png?width=670&height=266&name=unnamed%20(11).png)
- change the following rows:
replace - "https://schemas.xmlsoap.org/ws/2005/05/identity/claims/name" to "name" and its value to "user.givername"
Finally it should looks like this:
replace - "https://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname" to "surname" and its value to "user.surname"
.png?width=670&height=266&name=unnamed%20(12).png)
- Delete rows data:
-
I you would like to send also the user's Department, if the user needs to be assigned in Corporategift.com to a specific department (ex. sales/marketing)- Add new department attribute:
- Click on Add new claim

- - Set name to department
- set source attribute to user.department
- save it.
- Click on Add new claim
- Add new department attribute:
- Click Edit:
- Last step is to copy the required data and email it your account success manager so corporategift.com can complete the setup and configure the SSO:
- Copy Login URL and Azure AD Identifier from step 4.
- Download the Certificate (Base64) in SAML Signing Certificate section
- add the Login URL, Azure AD Identifier and the Certificate and in the my integrations section (from step 9) - and continue to configure the SSO on the corporategift.com account.

Return to CorporateGift.
Fill in:
- Microsoft Entra Identifier (Azure AD Identifier)
- Login URL
- Email Domains (This is used for SP Entity ID, meaning what email domains will be allowed to login from corporategift)
- Certificate (Base64)

Unlike the previous setup process, you do not need to send these values to the CorporateGift support team.
Simply paste the information into the configuration page and click Save Configuration.
If you selected Login Only, your setup is now complete.
Step 6 – Configure Automatic User Creation (Optional)
If Allow to create new users with SSO was enabled, click Continue to configure how new users will be created.
Choose one of the following permission modes.
Option 1 – Same Permissions for All Users
Choose:
Set same permissions for all Azure new users
Every newly created user will receive the same configuration.
Configure:
- User Role
- Tags
- Categories
- Campaign access
- Budget Entities
- Inventory Items
- Approver
- Spend Limits
Every new user created through Azure will receive these settings.

Option 2 – Permissions Based on Department
Choose:
Set permissions based on department
This option allows different departments to receive different permissions automatically.
Map Departments
For each department:
- Enter the department name exactly as it appears in Azure.
- Select the CorporateGift Tag that should be assigned.
- Click Add.
Example:
| Azure Department | CorporateGift Tag |
|---|---|
| Sales | Sales |
| Marketing | Marketing |
| HR | Human Resources |
Important
Department names must exactly match the values sent by Azure.

Configure Permissions
For every department mapping, configure:
- User Role
- Tags
- Categories
- Campaign Access
- Budget Entities
- Inventory
- Approver
- Spend Limits
Each department can have its own permission set.
You're Done
You should see the green "Installed" label
Once the app is confirmed, go to Azure Active Directory > Enterprise Applications, and select the application you registered for SSO.
- Under Properties, toggle Visible to users to yes.
- Under "User and Groups" Assign users groups to be able to use the SSO
- Now the app can be added to a Collection for My Apps page for Azure Initiated Login.

Enjoy Gifting!


