How to set up Azure SAML Single Sign-On (SSO) for Kahoot!
This guide provides clear, step-by-step instructions on how to configure Azure Single Sign-On (SSO) using SAML for Kahoot!. This setup ensures secure and seamless enterprise login for your team.
- How do I create and configure the application in Azure?
- What claim mappings are required for Kahoot!?
- How do I connect Azure to my Kahoot! account?
- How do I finalize the setup in Azure?
- How do I test my new Azure SAML configuration?
- FAQ
How do I create and configure the application in Azure?
To begin, you must establish the basic application framework within your Azure portal.
- Open your Azure portal and create a new Enterprise Application.
- Navigate to Single Sign-On.
- Under the Basic SAML configuration, you must add initial identifiers.
- Identifier (Entity ID): Click Add Identifier and enter https://placeholder/
- Reply URL (Assertion Consumer Service URL): Click Add Reply URL and enter https://placeholder/
- Click Save in the top right corner.
What claim mappings are required for Kahoot!?
Kahoot! requires specific user attributes to successfully map your Azure users to their Kahoot! accounts.
- Navigate to the Claims section and change the claim mappings to the following:
- your attribute for user email → email
- givenname → firstName
- surname → lastName
- Ensure that the “namespace” field is empty.
- Delete all other Additional Claims in Azure.
How do I connect Azure to my Kahoot! account?
You will need to exchange metadata between Azure and Kahoot! to establish the secure connection.
- In Azure, navigate to SAML Certificates and copy the App Federation Metadata URL.
- Log into your Kahoot! account and go to SSO & SCIM Management.
- Click Start setup.
- Under Step 2, select Azure as your provider.
- Paste the SAMLMetadata URL that you copied from Azure.
How do I finalize the setup in Azure?
- Copy the Entity ID from Kahoot! and paste it into Identifier (Entity ID) in Azure.
- Copy Assertion Consumer Service from Kahoot! and paste it into Reply URL (Assertion Consumer Service URL) in Azure.
How do I test my new Azure SAML configuration?
- Wait a few minutes for the changes to propagate in Kahoot!.
- Test the connection using your unique invitation link. This link can be found directly in the Kahoot! UI (labeled as Invitation link).
Your Azure SAML Single Sign-On should now be successfully configured with Kahoot!.
Connecting existing users to SSO
In order to connect existing users to SSO, please ask them to login using the Invitation link. Once they have authenticated via your IdP, they will be connected to SSO in Kahoot, and future logins via kahoot.com will enforce SSO login. When you invite new users, they will automatically receive the SSO Invitation link and be connected upon user creation.
FAQ
-
How do users login to Kahoot! through SSO?
Each organisation will be provided with a custom URL (magic link) by Kahoot!. Users can then click that link to login using Enterprise SSO. When they click on the link, they will be asked to authenticate themselves using their existing company login credentials if they’re not logged in already.
-
What do we need to do to set up the integration with our identity management platform with Kahoot!’s SSO?
Please follow the instructions in the setup guide for your respective identity provider. You will need admin access to your identity provider to configure Kahoot! as an app.
-
What personal information does Kahoot! Require our SSO provider about the user to create an account?
In the first version we need at least a user's email address. Our systems are GDPR compliant to protect user’s privacy. Our systems are GDPR compliant to protect users’ privacy. For more information, please see our Terms & Conditions and Privacy Policy.
-
What happens to the user’s existing account if they had already signed up to Kahoot!?
If we detect that the user already has a Kahoot! account associated with their work email, their existing account will be merged to join the new organization.
During the merging process, the user must first log in via SSO and then provide their old Kahoot! password to verify their account. At this step, a special verification screen will appear:
Once the merge is complete, the user will use the Enterprise SSO magic link to sign in to their Kahoot! account going forward.
-
What happens if a user already has an active subscription?
You will want to ensure that all of your kahoots are saved in your personal folder on your account (some of the upgraded accounts also have a "team folder" where your kahoots may have been saved). If your current account is under another email, ex: a personal email, and you want that to become your SSO work account - you will first need to go to your profile settings and change your email address to your Org email, then you will be able to accept and migrate over.
-
What happens when the users in the user group are higher than the number of licenses we have with Kahoot!?
We will block the users from joining the new org and sign up and ask them to contact their administrator to increase the license count.
-
What happens to users if we want to reduce the number of licenses?
Admin will have to remove those users from the Kahoot! user group in their admin portal before they can reduce the total number of licenses. See our billing and payment terms.
-
How do we offboard users from Kahoot?
Once you have removed the user’s access from your identity provider e.g. Okta, they will no longer be able to access Kahoot! anymore. However, to vacate their used license, you will need to login to Kahoot!’s user management page to remove the user from the interface to free up that license.
💡 Found this helpful? Subscribe to our Youtube channel for more tips and Kahoot! tutorials!
0 comments
Please sign in to leave a comment.