Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
In this article, you learn how to integrate ADP (OIDC) with Microsoft Entra ID. When you integrate ADP (OIDC) with Microsoft Entra ID, you can:
Use Microsoft Entra ID to control who can access ADP (OIDC). Enable your users to be automatically signed in to ADP (OIDC) with their Microsoft Entra accounts. Manage your accounts in one central location: the Azure portal.
Prerequisites
To get started, you need the following items:
- A Microsoft Entra subscription. If you don't have a subscription, you can get a free account.
- ADP (OIDC) single sign-on (SSO) enabled subscription.
Add ADP (OIDC) from the gallery
To configure the integration of ADP (OIDC) into Microsoft Entra ID, you need to add ADP (OIDC) from the gallery to your list of managed SaaS apps.
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > New application.
In the Add from the gallery section, enter ADP (OIDC) in the search box.
Select ADP (OIDC) in the results panel and then add the app. Wait a few seconds while the app is added to your tenant.
Configure Microsoft Entra SSO
Follow these steps to enable Microsoft Entra SSO in the Microsoft Entra admin center.
Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
Browse to Entra ID > Enterprise apps > ADP (OIDC) > Single sign-on.
Perform the following steps in the below section:
Navigate to Authentication tab on the left menu and perform the following steps:
Navigate to Certificates & secrets on the left menu and perform the following steps:
Create a Microsoft Entra test user
In this section, you create a test user called B.Simon.
- Sign in to the Microsoft Entra admin center as at least a User Administrator.
- Browse to Entra ID > Users.
- Select New user > Create new user, at the top of the screen.
- In the User properties, follow these steps:
- In the Display name field, enter
B.Simon
. - In the User principal name field, enter the username@companydomain.extension. For example,
B.Simon@contoso.com
. - Select the Show password check box, and then write down the value that's displayed in the Password box.
- Select Review + create.
- In the Display name field, enter
- Select Create.
Assign the Microsoft Entra test user
In this section, you enable B.Simon to use single sign-on by granting access to ADP (OIDC).
- Sign in to the Microsoft Entra admin center as at least a Cloud Application Administrator.
- Browse to Entra ID > Enterprise apps > ADP (OIDC).
- In the app's overview page, select Users and groups.
- Select Add user/group, then select Users and groups in the Add Assignment dialog.
- In the Users and groups dialog, select B.Simon from the Users list, then select the Select button at the bottom of the screen.
- If you're expecting a role to be assigned to the users, you can select it from the Select a role dropdown. If no role has been set up for this app, you see "Default Access" role selected.
- In the Add Assignment dialog, select the Assign button.
Configure ADP (OIDC) SSO
Below are the configuration steps to complete the OAuth/OIDC federation setup:
Sign into the ADP Federated SSO site with your ADP issued credentials (
https://identityfederation.adp.com/
).Select Federation Setup, select your Identity Provider as Microsoft Azure.
Enable OIDC Federation by selecting Enable OIDC Setup.
Perform the following steps in the OIDC Setup tab.
a. Copy the Relying Party Redirect URI value and use it later in the Entra configuration.
b. Paste the Open ID Connect metadata document value in the Well-known URL field which you have copied from Entra page and select RETRIEVE to auto populate the values in Endpoints.
c. In the Application Detail tab, paste the Application ID value in the Application Client ID field.
d. Paste the Application ID in the Audience field.
e. In the Application Client Secrets field, paste the value which you have copied from Certificates & Secrets in Entra.
f. The User Identifier should be the name of the attribute of your unique identifier which is synchronized between ADP and the identity provider.
g. Select SAVE.
h. Once you save the configuration, select ACTIVATE CONNECTION.