Read more
This article covers how to set up Single Sign On for Dalux Box, Tender, Field, InfraField, and Handover. If you want to read about Single Sign On for Dalux FM, please refer to this article: Single Sign On (SSO) with Microsoft Entra for Dalux FM.
Note
This article is intended to be read by system administrators with the assumption of having experience with Microsoft Entra.
Dalux does not offer any support on how to configure Microsoft Entra.
Single Sign On is only available for projects with a Pro license and company agreement.
The 'Single Sign On' feature enables your company to have a more secure environment by granting increased security regarding access to your Dalux projects. With this feature, you can control how your organization's users access projects by giving them the option or requiring them to use SSO.
This article will go over how to set up SSO for your projects using Microsoft Login (Microsoft Entra).
Login must be agreed on from both Dalux and the customer’s organization to allow users to log in using their Microsoft Login.
Set up Dalux in Microsoft Entra
Provide setup information to Dalux
First, contact Dalux Support to activate SSO via this link and provide the following information:
- SSO activation: Inform Dalux that you want to activate SSO for your organization
- Domains: List the domains that you want to activate SSO for
- Request DNS TXT record: Dalux Support will contact you with further information for the DNS TXT record used to verify that you are the controller of the registered domains
- Name of your organization in Dalux (Company profile)
Dalux Support will inform you when SSO has been activated.
Set up Dalux as an application in Microsoft Entra
When setting up SSO, you have different options to control how the login should look for your organization's users.
- Dalux enables Microsoft Login for the customer domain
- A system administrator with appropriate access in Microsoft Entra enters their mail address on the Dalux login page and clicks 'Microsoft Login'.
- In Microsoft Entra, you receive a request (example) and Dalux becomes available as an application which you can set up as you wish.
- Define the organization's login policy (see below).
- SSO is successfully activated for your Dalux organization and the domains you have specified.
Read more
You can find a guide about registering applications here: https://learn.microsoft.com/en-us/entra/identity-platform/quickstart-register-app
Activate approval requests
You can decide whether you want to grant consent for your organization's users in general or whether a reviewer should grant consent individually.
To do this, enable consent requests in Microsoft Entra and add at least one reviewer type. This way, when a user tries to log in with Microsoft Login, they will be prompted with an approval request form:
The reviewer can then approve or deny the request for this user in Microsoft Entra.
Managing login policies
You can specify how your organization's users are able to log into Dalux. It is possible to configure a domain as SSO only. This means that users registered with an email from the domain will only be allowed access to Dalux following successful authentication with SSO. This will prevent users from having separate passwords in Dalux.
You can change your domain settings by going to:
Company profiles
Select your company profile
Settings
'Managed domains'
Select a domain that is connected to your organization and set the 'Login policy'.
- Require AD: Requires users to log in with their Microsoft login
- Both AD and DaluxID: Users can choose to log in with Microsoft login or their Dalux account.
WARNING
When deactivating a user in your AD and you have set up your domain as 'Both AD and DaluxID', the user might still be able to access your Dalux project. Make sure to remove them from any user groups in the Dalux projects as well.