Blinq's Enforced SSO feature lets a workspace require all members to sign in using a configured SSO identity provider, based on the email domain of the user signing in. In this SAML SSO setup, Azure AD manages your organization's user accounts and credentials, and links with Blinq as the service provider for those users. When you enable SSO with Blinq, the login prompt for your team changes to only allow SSO.
What you'll need
A Blinq Enterprise subscription, with domains enabled by our Sales team
Owner access to your Blinq account
Azure AD Admin access
Both Blinq and Azure AD open in separate browser tabs
How enforced SAML SSO works
Your team attempts to log in to Blinq via SAML SSO.
Blinq sends a SAML request to Azure AD.
They are redirected to the Azure AD login page to complete login.
Azure AD checks your team member's credentials.
Azure AD sends a response to Blinq to verify the team member's identity.
Blinq accepts the response and logs the team member into their Blinq account.
Note: Blinq uses SAML 2.0 for all SAML SSO configurations. This includes configurations with supported identity providers and any custom configurations.
Step 1: Open Security in Blinq
Log in to the dashboard.
Go to the Team Members page and confirm you're listed as the Owner. Only the Owner can access the correct settings page.
Select Settings from the dropdown.
Open Security from the settings menu. Keep this tab open while you work, you'll need to copy information between Blinq and Azure AD in both directions.
Step 2: Configure SSO in Azure AD
Navigate to portal.azure.com. If you use Microsoft 365, this is still where you configure single sign-on for your organization.
Go to Enterprise Applications.
Select New Application.
Search for Blinq.
Select Blinq from the search results.
Select Create to continue.
Select Single Sign On from the manage menu.
Select SAML.
On Step 1, select Edit in the top right corner.
Go to the Security page in the Blinq dashboard and copy the ACS URL. It should look like auth.blinq.me/authorize/callback/ID.
In Entra, paste this into both the Reply URL (Assertion Consumer Service URL) and the Sign on URL.
On step 3, SAML Certificates, select Edit.
Select the Signing option and select Sign SAML response and assertion.
Select Save.
From the Download the Base64 Certificate section, open the certificate in a text editor and copy its contents into the Certificate field in the Blinq security form.
Copy the Login URL into the Single Sign on URL field on the Blinq security form.
Copy the Microsoft Entra Identifier into the Identity Provider Entity ID field on the Blinq security form.
Step 3: Enable SSO in Blinq
Toggle on Enforce SSO for all users.
With all fields complete, select Save.
Your SSO is now configured for your organization. All users logging in with email addresses ending in your domain are directed to log in using SSO.
Log out of Blinq. When you log back in, you should be taken through the Azure AD SSO flow.
Related guides
Using Okta instead? See Configuring Enforced SSO [Okta ID]. Setting up automatic user provisioning as well? See SCIM Provisioning Users [Azure AD].
Need help?
Reach out via the chat widget in the Help Center or email [email protected].
