1. Azure Portal, go to Azure Active Directory
2. On the left, click Enterprise Applications
3. On the All applications page, on the right hand side, click New application.
4. In the All Categories view of the gallery, on the top right, click on Non-gallery application.
5. Name the application FOS – <Company Name> . Azure AD shows the name in the myapps portal. Click Add.
6. After the application is created, on the left, in the Manage section, click Single sign-on.
7. On the right, click the SAML button.
8. In section 1 labelled Basic SAML Configuration, click the pencil icon.
12. Click Save. Then you might have to click the x on the top right to make it go away.
13. In section 2 labelled User Attributes & Claims, Click the pencil icon
14. Verified under the Required Claim section that the Unique User Identifier (Name ID) value is user.userprincipalname [nameid-format:emailAddress]
15. Click on X located in the upper right corner to close out this section.
16. In section 3 labelled SAML Signing Certificate, click the Download link in the Certificate (Base64) line.
17. Copy the App Federation Metadata Url
18. On the left hand side, under Manage section, click Users and groups
19. Use the normal process to assign Azure AD users and groups to this application. Click Assign.
1. The Azure AD Public Certificate you download step 14
2. The SAML metadata url from step 15
3. The Login URL from step 16
4. A test account username and password so Stellar can test.