Configuring SAML SSO still requires users be present in Commander with a matching email address. No SAML user provisioning is available at this time, but it is planned for a future version of Commander.
Azure Configuration
Commander Configuration
Azure Configuration
- Login to Azure and select Azure Active Directory as the service with which you want to be working.
- From the Manage menu, select Enterprise applications. Click New application.
- Click Create your own application and provide an appropriate name. If you will support Azure AD SSO for both the Commander admin console and the Service Portal, make sure that the name used will distinisguish one from the other.
- Assign a user to the application that has an appropriate role in either the Commander admin console or Service Portal.
- Open Single sign-on for the application. Select SAML.
- Edit Basic SAML Configuration using the appropriate settings for the application (Admin console or Service Portal) that you are configuring, as described below.
Commander Admin Console:
- Identifier (Entity ID): {Commander FQDN}
- Reply URL: https://{Commander FQDN}/saml/sso
- Sign on URL: https://{Commander FQDN}/saml/sso
- Logout URL: https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0
Commander Service Portal:
- Identifier (Entity ID): {Commander FQDN}/portal
- Reply URL: https://{Commander FQDN}/portal/saml/sso
- Sign on URL: https://{Commander FQDN}/portal/saml/sso
- Logout URL: https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0
- Edit User Attributes and Claims, adding a new claim. This step must be performed for both the Admin Console and Service Portal if you are configuring both applications.
- Click Add new claim.
- Fill out the following information
- Name: mail
- Source: Attribute
- Source attibute: user.mail
- Remove all other Additional claims.
- Review and confirm that the configuration is correct as shown below, and then download the Federation Metadata XML file.
Commander Configuration
Perform the following steps on the Commander application server.- On the Commander application server, launch an Administrator Command Prompt and browse to <INSTALL_DIRECTORY>\Embotics\vCommander\jre\bin\.
- Issue the following command to extract a key pair named "tomcat" from the original keystore as a file. Any passwords used will remain the same.
keytool -importkeystore -srckeystore ..\..\tomcat\conf\keystore -srcstoretype JKS -srcalias tomcat -srcstorepass changeit -destkeystore ..\..\tomcat\conf\saml-keystore.p12 -deststoretype PKCS12 -deststorepass changeit -destalias saml
- Retrieve the <INSTALL_DIRECTORY>\Embotics\vCommander\tomcat\conf\saml-keystore.p12 file and store it securely. Given the command above, the keystore:
- will contain a key pair named saml
- is protected with the password changeit
- Browse to Configuration > Identity and Access and switch to the Authentication tab.
- Complete the following for both the SAML Single Sign-On for Commander (Admin Console) and SAML Single Sign-On for Service Portal as necessary:
- Click Edit.
- Check Enabled.
- Select the File radio button and click Add. Browse to and select the metadata.xml file downloaded in Step 9 of the Azure Configuration of the previous section.
- In the SAML Key Pair section, click Add. Browse to and select the saml-keystore.p12 file saved in Step 3 of the last procedure above. Provide the Keystore Password, Key Pair Alias, and Key Pair Password as set in the previous section.
- Confirm the Commander External URL / Service Portal External URL matches the Identifier (Entity ID) configured in Azure for the application. (Step 6 of the Azure Configuration above)
- Enter the User ID Attribute mail.
- Unless you elect to change this, the default hash algorithm will be SHA256.
- Check Signed Metadata.
- Enter https://login.microsoftonline.com/common/wsfederation?wa=wsignout1.0 as the Sign Out URL.
- Click OK to save your configuration.
Reload your browser to make sure nothing has been cached that will interfere with your newly configured SSO. When you open the Commander portal you have configured, you will be redirected to an Azure AD login screen, where you can login in with any multi-factor authentication you have have configured.
Note: You can continue to login to Commander's Admin console bypassing SAML using the following URL: https://{Commander FQDN}/?defaultLogin
Was this helpful?
Related Articles
Configure SAML SSO in Azure AD for on premises Snow License Manager 6Number of Views How to Configure SVM SSO with Azure 23Number of Views Adding Azure Public Images to Snow Commander 8Number of Views Windows Azure Active Directory Berechtigungen für Spider Azure AD API Connector 9Number of Views How to configure PingOne for Snow Atlas SSO 43Number of Views
Revenera Assistant
Online
Hi, I am Reva - Ask me anything.
Updates
No new updates
Chat
Home
Updates
/**/
Thanks for the feedback!
Your feedback has been saved.Rate this response:
1
2
3
4
5
Add Additional feedback ( Optional )
0/240
English
English
Language changed successfully
Something went wrong
Email sent successfully
Something went wrong
Case create successfully
Are you sure you want to cancel
the case creation?
Please select a product to submit the case.
Please select a product version to submit the case.
0/255
Upload Attachment
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to cancel the case creation?
Case closed successfully
File Upload
Maximum file size allowed is 3 MB.
File type not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
File Upload
Maximum file
size allowed is 3 MB.
File type
not supported.
Supported file types:
Documents (.txt, .doc, .docx, .pdf), Images (.jpg, .png), Comma Separated Files
(.csv) Speadsheets (.xlsx, .xls)
© 2026 Flexera Software. All Rights Reserved.
Case id: 00001065
Activity: Status change: 2 hours ago