SSO with Azure
Azure integration is available on Wrike Enterprise accounts.
⏱ 1 min read
Azure Active Directory (Azure AD) is Microsoft’s cloud-based identity and access management service. Azure AD provides a SAML SSO service that allows users to enter login information once and then access all work applications and tools, including Wrike, without being prompted to log in to each of them.
Please note, that user attribute provisioning can be set up only with the help of our Support Team. More information, including details about the benefits and limitations of setting up single sign-on, can be found on our SSO help page.
- Note! The configuration of single logout for Azure AD is not supported.
Before you begin
- You'll need your account ID to set up the integration. To find it, log in to your Wrike account via a browser and locate the numbers between “acc=” and “#” in the address bar – this is your account ID.
For example, account ID 123456 would look like this in the address bar: https://www.wrike.com/workspace.htm?acc=123456#...
- Please note: After you go through all the steps of the setup in your Azure account, you'll still need to contact Wrike support to finalize the integration.
Set up the integration
- Go to the Azure portal and log in to your admin account.
- Select Azure Active Directory from the left-hand navigation panel.
- Select “Enterprise applications” from the list.
- Next, select “All applications”. 1
- Click “New application” at the top of the page. 2
- Scroll to the “Add from gallery” section and search for Wrike using the search bar, or select it from the list below.
- Click “Add” from the bottom right-hand corner. The application is added.
- Select “Single sign-on” from the left-hand panel. 3
- Select a single sign-on method. To integrate Azure with Wrike you need to select SAML from the list. 4
- In the next window, locate the “Basic SAML Configuration” 5 section and click on the pencil icon in the upper-right corner.
- In the window that opens, enter the following information:
- In the field under “Identifier (Entity ID)” 6 enter https://www.wrike.com/account/your_account_ID
- In the field under “Reply URL (Assertion Consumer Service URL)” 7, enter the following three URL strings:
- https://login.wrike.com/saml/SSO/account/your_account_ID - make this URL the default one using the checkbox to the right
NOTE: the “SSO” part of all URLs must be all uppercase letters.
- Leave the fields “Sign on URL”, “Relay State”, and “Logout URL” blank.
- Click the “Save” 8 button at the top.
- Then click “X” in the upper-right corner to proceed to the next step.
- Scroll down to the “User Attribute and Claims” section and click on the pencil icon in its upper-right corner.
- In the window that opens, click on the “Emailaddress” claim.
- In the "Source attribute" drop-down menu select “user.mail”.
- Click “Save” at the top of the window.
- Close the current window by clicking the “X” in the upper-right corner.
- Click “Save”, again, to save the “User Attribute and Claims” settings.
- Then click the “X” icon in the upper-right corner to proceed to the next step.
- Scroll down to the “SAML Signing Certificate” section.
- Click “Download” 9 located next to the “Federation metadata XML”.
- The generated XML file is downloaded. You can upload the generated metadata from the file to your Wrike account as described here, and then contact support to finalize the setup.
Alternatively, you can send the generated XML file to Wrike support and indicate the date on which you’d like your integration to start working. You can also add the exact time when the integration should be enabled (in that case, please also provide your time zone).
Once the support receives your request, they’ll finalize the SAML integration setup for you. As soon as the integration is finalized you will be able to access Wrike from within your Azure AD.