This site uses different types of cookies, including analytics and functional cookies (its own and from other sites). To change your cookie settings or find out more, click here. If you continue browsing our website, you accept these cookies.
6/17/21: We have completed maintenance for the Search functionality on the Community. If you are seeing any issues, please try to clear your cache first. If the issue persists please email Community@alteryx.com
Starting in 2018.2, Alteryx Server supports a majority of identity provider (IdP) connections that adhere to the SAML 2.0 Standard and allows for single sign on to the Alteryx Gallery. This article covers the configuration and setup for both Azure AD and Alteryx Server.
Alteryx Server access with permissions to configure Alteryx System Settings
SSL Enabled for Gallery URL (HTTPS)
Access (typically Admin) to create and edit enterprise applications within Azure Active Directory
Procedure - Part 1 - Azure Configuration
In the Azure portal > Select Azure Active Directory > Enterprise Applications and then select + New Application or select one that was already created for Alteryx Gallery. Here is the Microsoft page for more information on creating applications.
Select the application that will be used for the SAML configuration and then click on Single Sign-On. This will bring up the configuration page for the SAML information. The fields that are required are below:
Unique User Identifier(Name ID) = set to Email Address and Source Attribute set to user.userprincipalname
firstName = user.givenname
lastName = user.surname
email = user.userprincipalname
**Note** Remove the Namespaces that auto populate for all addtional Claims only and make sure firstName and lastName are in camel case.
Additional claims - email
SAML Signing Certificate
App Federation Metadata URL = You will need this URL for the Alteryx Server Settings.
**Note** This is where you can manually download the x.509 certificate
Set up Alteryx Gallery (Application Name)
Azure AD Identifier = You will need this URL for the Alteryx Server Settings
Part 2 - Alteryx System Settings
In the server System Settings you will need to make sure SSL is enabled under Gallery > General. You will need to have a certificate installed on the server; more information can be found here .
Next, Select SAML Authentication > IDP Metadata URL > and enter the three URLs.
ACS Base URL = This field will auto-populate and will be configured with HTTPS. This is the Gallery URL with "/aas" at the end. IDP URL = This is the Azure AD Identifier URL from the Azure SSO page IDP Metadata URL = This is the App Federation Metadata URL from the Azure SSO Page
Finally, once these are all entered, hit Verify IDP to test the connection. There is also a way to test the connection from the Azure portal as well. Then select Next through the rest of the settings to save the configuration. Once everything is saved, navigate to the Gallery in a browser and hit Log In where you will be prompted with a Microsoft Azure sign-in page.