Who can use this feature?
Available on Enterprise plan.
Accessible to Owners and Admins on Web App.
To enable Single Sign-On (SSO) functionality for your Alohi applications, Fax.Plus or Sign.Plus, via Microsoft Entra ID, facilitating seamless access for your team members directly from their Entra ID dashboard to Fax.Plus or Sign.Plus, it's essential that you possess administrative rights for both Fax.Plus/Sign.Plus and Microsoft Azure.
Step 1: Add the Alohi app on Microsoft Entra ID
- Sign in to the Azure portal and open Microsoft Entra ID.
- Click + Add > Enterprise application (or go to Enterprise applications > New application).
- In the Microsoft Entra App Gallery, search for Alohi and select the Alohi application published by Alohi. Make sure you pick the app named "Alohi" - it supports SAML-based sign-on and automatic provisioning for both Fax.Plus and Sign.Plus.
- Click Create and wait a few moments while the application is added to your directory.
Step 2: Configure SAML sign-on in Entra ID
- In the Alohi application, go to Manage > Single sign-on and select SAML as the sign-on method.
-
Entra ID will ask to save Alohi's fixed sign-on settings:
- Identifier (Entity ID): https://sso.alohi.com/metadata
- Reply URL (Assertion Consumer Service URL): https://sso.alohi.com/login
Click Yes to save them. These values are pre-configured for the Alohi app, so you don't need to enter them manually.
- On the SAML-based Sign-on page, collect the details you'll need on the Fax.Plus/Sign.Plus side:
- In the SAML Certificates section, next to Certificate (Base64), click Download. Open the downloaded .cer file with a plain text editor (TextEdit on Mac, Notepad on Windows) and keep it ready to copy.
- In the Set up Alohi section, copy the Login URL and the Microsoft Entra Identifier.
Step 3: Activate SSO on Fax.Plus or Sign.Plus
- Log in to your Fax.Plus account and go to Settings > Security.
- In the Access Management box, next to Single Sign-On (SSO), click Activate.
- To the right of Single Sign-On (SSO), click on Activate.
- In the Identity Provider (SAML) step, fill in the details from Entra ID:
- Single Sign-On URL: paste the Login URL from Step 2.
- Entity ID: paste the Microsoft Entra Identifier from Step 2.
- X.509 Certificate: paste the full content of the Base64 certificate file you opened in your text editor.
- Refresh Token Lifetime (Seconds): keep the default (3600) unless your security policy requires a different value.
- SSO Bypass: keep "Allow using email and password to login" checked if you want members to be able to sign in with their password as a fallback.
- Select “Alohi SSO” as the SSO Type
- Finally, press Next
Step 4: Set up Automatic User Provisioning
- The User Provisioning (SCIM) step shows the two values you'll need in Entra ID - keep them ready to copy:
- Tenant URL: https://sso.alohi.com/scim/v2
- SCIM Token
- Under Product Assignment, check Automatically add new users to Fax.Plus and/or Automatically add new users to Sign.Plus, so the users you assign in Entra ID are created automatically. If Sign.Plus selected seats must be available on your plan.
- Click Done. Single Sign-On now shows as Active in your Security settings.
- Back in the Entra ID portal, open the Alohi application and go to Manage > Provisioning, then click + New configuration.
- Select Get Started, and set the mode to Automatic.
- Under Admin credentials:
- Tenant URL: paste https://sso.alohi.com/scim/v2
- Secret token: paste the SCIM Token from your Fax.Plus dashboard.
- Click Test connection to verify the setup, then click Create.
Step 5: Assign your users
- In the Alohi application in Entra ID, go to Manage > Users and groups.
- Click Add user/group and select the members who should have access. Assigned users are created on Fax.Plus or Sign.Plus automatically through provisioning.
- They can now sign in to their account through the Alohi SSO integration.
How your members sign in
- On the Fax.Plus login page, members enter their email address and click Sign In.
- What happens next depends on the SSO Bypass setting:
- SSO Bypass off: members are redirected straight to Microsoft Entra ID to authenticate. Once signed in, they land directly in their account. Password login is not available.
-
SSO Bypass on: After entering their email, members see a screen with two options: SSO Login and Password.
- Choosing SSO Login continues through your identity provider as above.
- Choosing Use Password lets them sign in with their email and password as usual.
Benefit: By setting up the Alohi SSO, you streamline access to both Fax.Plus and Sign.Plus and centralize user management in Microsoft Entra ID, giving your organization a more secure and efficient document workflow.
Updating user information (coming soon)
If anything changes on your side (users' email address, domain, or name), you'll need to make the update on the Azure side. Please ensure you have the right permissions to make this change.
Azure will automatically sync the update, but this may take up to 40 minutes. If you need the update applied sooner, use on-demand provisioning.