Step 1: Create a New Productive Application in Entra
Go to Enterprise Applications and click on New Application.
Search for Productive, click on the Productive tile, and then click Create.
Step 2: Check User Information for Automatic Provisioning
Ensure all your users have their first and last names set up.
Navigate to Users > All users and verify that each user has their first and last name assigned.
If not, click on the Edit button, go to the Identity tab, enter the user's first and last names, and click Save.
Step 3: Assign Users to the Application
To allow users to log in via Entra SSO, assign them to the newly created application.
Select your application, navigate to Users and Groups, and click on Add user/group.
Select all the users you want to allow to sign in via Entra SSO, click on Select, and then click on Assign to finalize the selection.
Step 4: Copy SSO Data from Productive to Entra
Navigate to Single sign-on and choose SAML as the single sign-on method.
Click the Edit button in the Basic SAML Configuration section.
Go to Productive Single Sign-On settings and copy the Audience URI value.
Return to Entra and paste the value into the Identifier (Entity ID) field. Delete any other entries and mark this one as default.
Go back to Productive settings and copy the Single sign-on URL.
Return to Entra, paste it into the Reply URL (Assertion Consumer Service URL), and click Save.
Step 5: Copy SSO Data from Entra to Productive
Under SAML Certificates, copy the App Federation Metadata URL.
Go to Productive SSO settings and paste it into the Metadata URL field.
Return to Entra and copy the Login URL.
Go to Productive SSO settings and paste it into the Identity Provider Single Sign-on URL.
Click on Enable SSO.
Step 6: Set Up Attributes for Provisioning in Entra
Click on Edit in the Attributes & Claims section.
Click on the required claim.
In the Additional Claims section:
Step 7: Test SSO
Return to your Entra Productive application, click Single sign-on, and then click Test at the bottom.
Click on Test sign in.
Alternatively, go to the Productive login screen and click Use single sign-on (SSO) to test the setup.