Snow Commander supports SAML-based Single Sign-On (SSO) by integrating with Azure Active Directory (Azure AD). This configuration enables multi-tenant RBAC and secure user authentication. While SAML provisioning is not available yet, user accounts must exist in Commander and match their Azure AD email addresses for successful logins.

Azure AD Configuration
- Log in to the Azure portal and select Azure Active Directory.
- From the Manage menu, choose Enterprise applications and click New application.
- Select Create your own application, provide an application name, and ensure names clearly distinguish the Admin Console and Service Portal if configuring both.
- Assign appropriate users to the application.
- Open Single sign-on and select SAML.
- Edit Basic SAML Configuration with these values:
- Commander Admin Console:
- Identifier (Entity ID):
{Commander FQDN} - Reply URL:
https://{Commander FQDN}/saml/sso - Sign on URL:
https://{Commander FQDN}/saml/sso - Logout URL:
https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0
- Identifier (Entity ID):
- Commander Service Portal:
- Identifier (Entity ID):
{Commander FQDN}/portal - Reply URL:
https://{Commander FQDN}/portal/saml/sso - Sign on URL:
https://{Commander FQDN}/portal/saml/sso - Logout URL:
https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0
- Identifier (Entity ID):
- Commander Admin Console:
- Edit User Attributes and Claims:
- Click Add new claim.
- Enter:
- Name:
mail - Source:
Attribute - Source attribute:
user.mail
- Name:
- Remove all additional claims.
- Review, confirm configuration, and download the Federation Metadata XML file.
Commander Application Server Configuration
- On the Commander server, open an Administrator Command Prompt and navigate to:
<INSTALL_DIRECTORY>\Embotics\vCommander\jre\bin\ - Run the following command to create the SAML keystore:
keytool -importkeystore -srckeystore ..\..\tomcat\conf\keystore -srcstoretype JKS -srcalias tomcat -srcstorepass changeit -destkeystore ..\..\tomcat\conf\saml-keystore.p12 -deststoretype PKCS12 -deststorepass changeit -destalias saml - Securely store the generated file:
- Path:
<INSTALL_DIRECTORY>\Embotics\vCommander\tomcat\conf\saml-keystore.p12 - Contains key pair
samland uses the passwordchangeit.
- Path:
Commander Admin Console Configuration
- Log in as a superuser and navigate to Configuration > Identity and Access, then the Authentication tab.
- For SAML Single Sign-On for Commander and Service Portal:
- Click Edit, check Enabled, then select File and upload the downloaded
metadata.xml. - In SAML Key Pair, upload the
saml-keystore.p12file and provide the keystore password, alias, and key pair password. - Confirm external URLs match the Entity ID configured in Azure.
- Enter User ID Attribute:
mail. - Keep default hash algorithm (SHA256), check Signed Metadata, and provide Sign Out URL:
https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0 - Click OK to save.
- Click Edit, check Enabled, then select File and upload the downloaded
- Reload the browser to clear cached data.
Outcome
After configuration, users are redirected to Azure AD for SSO login when accessing Commander or the Service Portal. If needed, bypass SAML for the Admin Console using:
https://{Commander FQDN}/?defaultLogin
Was this helpful?
Related Articles
How to configure Active Directory SSO for Spider 13Number of Views Configure Active Directory Federation Services as an Identity Provider for SAML 2.0 Single Sign-On 20Number of Views Adobe Acrobat DC edition information is not gathered in inventory from Azure Active Directory user profiles 6Number of Views Windows Azure Active Directory Berechtigungen für Spider Azure AD API Connector 12Number of Views How to Configure SVM SSO with Azure 26Number of Views
Revenera Assistant
Online
Hi, I am Reva - Ask me anything.
Updates
No new updates
Chat
Home
Updates
/**/
Thanks for the feedback!
Your feedback has been saved.Rate this response:
1
2
3
4
5
Add Additional feedback ( Optional )
0/240
English
English
Language changed successfully
Something went wrong
Email sent successfully
Something went wrong
Case create successfully
Are you sure you want to cancel
the case creation?
Please select a product to submit the case.
Please select a product version to submit the case.
0/255
Upload Attachment
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to cancel the case creation?
Case closed successfully
File Upload
Maximum file size allowed is 3 MB.
File type not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Revenera Assistant
© 2026 Flexera Software. All Rights Reserved.
Case id: 00001065
Activity: Status change: 2 hours ago