Skip to main content
If you encounter any issues or need additional assistance, we offer a free setup call.
You can submit a support request at support@studystash.com.

Step 1: University provides StudyStash with Identity Provider (IdP) information

Fill out the following form to provide details to our team: https://internal.support.studystash.com/servicedesk/customer/portal/34/create/158 Alternatively you can contact us at support@studystash.com with this information if you would prefer.
Note - Providing StudyStash with a user account allows us to test that SSO has been set up correctly, and more easily troubleshoot any issues that arise.

Step 2: StudyStash provides Service Provider (SP) information

Once we have received the form above our team will be able to provide you with a URL containing our Service Provider metadata document (XML). StudyStash will provide:

Reply URL (Assertion Consumer Service URL)

To be provided by StudyStash after completion of SSO Configuration form

Identifier (Entity ID)

To be provided by StudyStash after completion of SSO Configuration form

Required NameId policy:

urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress

Required Attributes:

Email Address

  • Claim name: urn:oid:0.9.2342.19200300.100.1.3

  • Value: user.mail

Optional Attributes:

First name

  • Claim name: urn:oid:2.5.4.42

  • Value: user.givenName

Last name

  • Claim name: urn:oid:2.5.4.4

  • Value: user.sn

University to Provide:

App Federation Metadata Url

To be provided to StudyStash

Example: Azure Active Directory

The following steps are required to set up StudyStash as a service provider with Azure Active Directory (also known as Microsoft Entra ID):

3.1) Create a new Enterprise Application

  1. Navigate to the Microsoft Azure portal and sign in as a user with permissions to create enterprise applications.
  2. Under the Azure Services section, find and select Enterprise applications. You may have to go to the All services page and then scroll down to the Identity section to find it.
SSO Setup Guide — screenshot

Figure 1. SSO Setup Guide — screenshot

  1. Select New application. You’ll be redirected to the Browse Microsoft Entra Gallery page.
  2. Select Create your own application.
SSO Setup Guide — screenshot

Figure 2. SSO Setup Guide — screenshot

  1. In the popup that opens:
    1. Provide a name of the application (StudyStash).
    2. Select “Integrate any other application you don’t find in the gallery (Non-gallery)”.
    3. Click “Create”.
SSO Setup Guide — screenshot

Figure 3. SSO Setup Guide — screenshot

3.2) Assign users or groups

Now the enterprise app is created, you need to assign users or groups before they can use it to log in. More details are provided from Microsoft: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/assign-user-or-group-access-portal?pivots=portal

3.3) Set Basic SAML Configuration

  1. Select the Single sign-on option in the Manage menu and choose SAML. You’ll be redirected to the Set up Single Sign-On with SAML page.
SSO Setup Guide — screenshot 4

Figure 4. SSO Setup Guide — screenshot 4

  1. Find the Basic SAML Configuration section.
  2. Select Edit. The Basic SAML Configuration panel will open.
  3. Add the provided Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) values. These values will be saved automatically.

Field

Value

Reply URL (Assertion Consumer Service URL)

Example:
https://sso.studystash.com/proxy/acs

Identifier (Entity ID)

Example:
https://sso.studystash.com/metadata

  1. Select Save at the top of the panel. Close the panel.

3.4) Verify correct configuration of attributes and claims

  1. Still on the Set up Single Sign-On with SAML page, find the Attributes & Claims section.
  2. Select Edit.
  3. Verify the following attributes and values are present:

Required Attributes:

Email Address

  • Claim name: urn:oid:0.9.2342.19200300.100.1.3

  • Value: user.mail

Optional Attributes:

First name

  • Claim name: urn:oid:2.5.4.42

  • Value: user.givenName

Last name

  • Claim name: urn:oid:2.5.4.4

  • Value: user.sn

3.5) Share the application’s metadata URL

  1. Still on the Set up Single Sign-On with SAML page, find the SAML Certificates section.
  2. Copy the App Federation Metadata Url, and send this to your StudyStash contact. This is the final piece of information we need to enable SAML.
SSO Setup Guide — screenshot

Figure 5. SSO Setup Guide — screenshot

  1. The setup is now complete!