> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://docs.brainframe.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# SAML SSO Microsoft Entra

# 🔑 **SAML SSO Microsoft Entra**  
> **"Schakel veilige single sign-on in met Microsoft Entra en Brainframe GRC."**  
> *Volg deze stappen om SAML-authenticatie te configureren tussen je Entra-tenant en Brainframe GRC.*  



## 1️⃣ Applicatie aanmaken  

1. Ga naar het **Entra admin center** → [https://entra.microsoft.com/#home](https://entra.microsoft.com/#home) en klik op **New application**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-72_8vz80.png =541xauto) 

2. Selecteer **Create your own application**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-20_fswyie.webp =355xauto) 

3. Voer een **naam** in voor je applicatie, kies **Non-gallery application** en klik op **Create**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-73_10zbnyc.png =515xauto) 

| 📌 Tip: Gebruik een beschrijvende naam (bijv. Brainframe GRC SSO) zodat deze eenvoudig te herkennen is.  



## 2️⃣ Entra-applicatie configureren  

1. Ga naar **Single sign-on** en selecteer **SAML**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-21_1dobnrt.webp =647xauto) 

2. Klik op **Edit** in het blok **Basic SAML configuration**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-74_11dh4p3.png =716xauto) 

3. Haal de vereiste waarden op uit **Brainframe Werkruimte-instellingen → Authenticatie** en voer deze in bij Entra. Laat de overige velden leeg. Klik op **Save**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-22_14zt5r3.webp =586xauto) 

4. Bewerk het blok **Attributes & claims**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-23_1rvx0tx.webp =664xauto) 

5. Verwijder alle niet-vereiste claims onder **Additional claims** door te klikken op de **3 puntjes → Delete**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-75_1itpuy9.png =584xauto) 

6. Voeg nieuwe claims handmatig toe via **Add new claim**.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-24_1ndmlcy.webp) 

7. Maak de volgende **hoofdlettergevoelige claims** aan:  
* `firstname`  
* `lastname`  
* `WorkspaceId`  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-25_zcezq4.webp =364xauto) 
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-26_mbcm4x.webp =352xauto) 

||| ⚠️ **Let op:** Claimmnamen moeten exact overeenkomen. Gebruik `WorkspaceId` (niet `Workspaceid`).  

✅ Voorbeeld eindconfiguratie:  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-77_h13lt0.png =659xauto) 



## 3️⃣ Brainframe Configuratie  

Wanneer Entra klaar is, configureer je de Brainframe GRC-zijde in **Werkruimte-instellingen → Authenticatie**.  

![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-78_ln7til.png =666xauto) 

1. Kopieer de **Login URL** uit Entra (SSO-pagina) → plak deze in **IdP Single Sign-On (SSO) Login URL** in Brainframe.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-27_u3ci0x.webp =756xauto) 

2. Download het **SAML Certificate (Base64)** → Kopieer de tekst (verwijder de regels **BEGIN/END CERTIFICATE**) → Plak dit in **IdP application certificate** in Brainframe.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-28_12u36tl.webp =639xauto) 



## 4️⃣ Integratie testen  

1. Voeg gebruikers toe aan de Entra-applicatie.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-29_1s3e5fb.webp =452xauto) 

2. Test de login-flow van de applicatie.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-30_yflg4x.webp =652xauto) 

3. Toegewezen gebruikers zien de app nu beschikbaar in hun Entra-portaal.  
![](https://storage.crisp.chat/users/helpdesk/website/-/3/f/2/6/3f26ce462760bc00/image-79_1n2a84s.png =417xauto) 



## 5️⃣ Veelvoorkomende fouten & oplossingen  

||| ❌ *Failed to read asymmetric key* → je moet het “IdP application certificate” in de Brainframe GRC-instellingen bijwerken met het IdP BASE64-certificaat (zonder de BEGIN/END Certificate-regels).  

||| ❌ *Attributes mismatch* → Alle attributen zijn hoofdlettergevoelig (bv. WorkspaceId moet exact overeenkomen).  
