How to set up Azure SAML Single Sign-On (SSO) for Kahoot!
This guide provides clear, step-by-step instructions on how to configure Azure Single Sign-On (SSO) using SAML for Kahoot!. This setup ensures secure and seamless enterprise login for your team.
- How do I create and configure the application in Azure?
- What claim mappings are required for Kahoot!?
- How do I connect Azure to my Kahoot! account?
- How do I finalize the setup in Azure?
- How do I test my new Azure SAML configuration?
- FAQ
How do I create and configure the application in Azure?
To begin, you must establish the basic application framework within your Azure portal.
- Open your Azure portal and create a new Enterprise Application.
- Navigate to Single Sign-On.
- Under the Basic SAML configuration, you must add initial identifiers.
- Identifier (Entity ID): Click Add Identifier and enter https://placeholder/
- Reply URL (Assertion Consumer Service URL): Click Add Reply URL and enter https://placeholder/
- Click Save in the top right corner.
What claim mappings are required for Kahoot!?
Kahoot! requires specific user attributes to successfully map your Azure users to their Kahoot! accounts.
- Navigate to the Claims section and change the claim mappings to the following:
- your attribute for user email → email
- givenname → firstName
- surname → lastName
- Ensure that the “namespace” field is completely empty.
- Delete all other Additional Claims in Azure.
How do I connect Azure to my Kahoot! account?
You will need to exchange metadata between Azure and Kahoot! to establish the secure connection.
- In Azure, navigate to SAML Certificates and copy the App Federation Metadata URL.
- Log into your Kahoot! account and go to SSO & SCIM Management.
- Click Start setup.
- Under Step 2, select Azure as your provider.
- Paste the SAMLMetadata URL that you copied from Azure.
How do I finalize the setup in Azure?
Now that Kahoot! has Azure's metadata, you must replace your temporary placeholders in Azure with Kahoot!'s actual metadata.
- Copy and save your Enterprise Single Sign-on link from Kahoot!, which becomes available after finishing the previous step.
- Copy the Kahoot! metadata link and open it in a new browser tab.
- From the Metadata XML file, locate and copy the following values:
- Find the <EntityDescriptor> tag and copy the entityId value (e.g., https://access-2.kahoot.com/auth/realms/kahoot-enterprise).
- Find the <AssertionConsumerService> tag and copy the Location value (e.g., https://access-2.kahoot.com/auth/realms/kahoot-enterprise/broker/{uniqueAlias}/endpoint).
- Go back to Azure and replace your temporary placeholders with these values:
- Identifier (Entity ID) gets the entityId value.
- Reply URL gets the Location value.
- Leave the following fields blank: Sign-on URL, Relay State, and Logout URL.
How do I test my new Azure SAML configuration?
- Wait a few minutes for the changes to propagate in Kahoot!.
- Test the connection using your unique invitation link. This link can be found directly in the Kahoot! UI (labeled as Invitation link).
- Alternatively, format your test link as: https://enterprise.kahoot.com/{idpAlias}/login (replace idpAlias with the alias from your Enterprise SSO URL).
Your Azure SAML Single Sign-On should now be successfully configured with Kahoot!.
FAQ
-
How do users login to Kahoot! through SSO?
Each organisation will be provided with a custom URL (magic link) by Kahoot!. Users can then click that link to login using Enterprise SSO. When they click on the link, they will be asked to authenticate themselves using their existing company login credentials if they’re not logged in already.
-
What do we need to do to set up the integration with our identity management platform with Kahoot!’s SSO?
Please follow the instructions in the setup guide for your respective identity provider. You will need admin access to your identity provider to configure Kahoot! as an app.
-
What personal information does Kahoot! Require our SSO provider about the user to create an account?
In the first version we need at least a user's email address. Our systems are GDPR compliant to protect user’s privacy. Our systems are GDPR compliant to protect users’ privacy. For more information, please see our Terms & Conditions and Privacy Policy.
-
What happens to the user’s existing account if they had already signed up to Kahoot!?
If we detect that the user already has a Kahoot! account associated with their work email, their existing account will be merged to join the new organization.
During the merging process, the user must first log in via SSO and then provide their old Kahoot! password to verify their account. At this step, a special verification screen will appear:
Once the merge is complete, the user will use the Enterprise SSO magic link to sign in to their Kahoot! account going forward.
-
What happens if a user already has an active subscription?
You will want to ensure that all of your kahoots are saved in your personal folder on your account (some of the upgraded accounts also have a "team folder" where your kahoots may have been saved). If your current account is under another email, ex: a personal email, and you want that to become your SSO work account - you will first need to go to your profile settings and change your email address to your Org email, then you will be able to accept and migrate over.
-
What happens when the users in the user group are higher than the number of licenses we have with Kahoot!?
We will block the users from joining the new org and sign up and ask them to contact their administrator to increase the license count.
-
What happens to users if we want to reduce the number of licenses?
Admin will have to remove those users from the Kahoot! user group in their admin portal before they can reduce the total number of licenses. See our billing and payment terms.
-
How do we offboard users from Kahoot?
Once you have removed the user’s access from your identity provider e.g. Okta, they will no longer be able to access Kahoot! anymore. However, to vacate their used license, you will need to login to Kahoot!’s user management page to remove the user from the interface to free up that license.
💡 Found this helpful? Subscribe to our Youtube channel for more tips and Kahoot! tutorials!
0 comments
Please sign in to leave a comment.