On this page
This guide shows how to configure Azure AD SAML Single Sign On (SSO) for Brilliant Assessments. This article assumes you already understand Azure Active Directory and the Azure Portal.
1. Prerequisites
- Access to the Azure Portal with permissions to create Enterprise Applications.
- Access to Brilliant Assessments Site Settings.
- Your Brilliant Assessments subdomain (example: mycompany.brilliantassessments.com).
2. Create the Azure Enterprise Application
- Login to the Azure Portal.
- Navigate to Azure Active Directory.
- Select Manage → Enterprise Applications.
- Click New Application → Create your own application.
- Name it something clear, e.g. Brilliant Assessments SSO.
- Choose Non-Gallery → Click Create.
Note: You may also wish to assign users or groups to this application, please see Azure AD Help if required
3. Configure SAML Settings in Azure
- Select Single Sign On → Click Get Started.
You will now see the Azure SAML configuration screen:
Enter the following:
-
Identifier (Entity ID):
http://BrilliantAssessmentsServiceProviderMust match exactly. -
Reply URL (Assertion Consumer Service URL):
https://subdomain.brilliantassessments.com/Account/AssertionConsumerService
Replace subdomain with your company's subdomain.
Example:https://mycompany.brilliantassessments.com/Account/AssertionConsumerService
Delete any default values Azure pre-populates → Click Save.
4. Download the SAML Certificate
- Scroll to Section 3 – SAML Signing Certificate.
- Download the Base64 version.
This certificate will be uploaded into Brilliant Assessments shortly.
5. Configure SSO in Brilliant Assessments
Open a new browser tab and login to Brilliant Assessments.
- Go to Site Settings > Integrations > SSO tab
- Tick the "Use SSO" checkbox
- There will be SSO configuration fields appear underneath
- Click Save
When you click on the SSO tab, you will see the SSO Config tab.
- Copy the Azure Azure AD Identifier into the field SSO Issuer URL.
- Upload the Base64 certificate you downloaded.
- Copy the Sign-on URL and Logout URL from Azure → paste into their matching fields.
- Tick:
- Sign Logout Request
- Require Logout Signed
- Enforce SSO (optional). When this checkbox is ticked, users can only sign in through SSO. The standard Brilliant Assessments login screen (email and password) is disabled for the Admin, Manager, and Respondent roles - only SSO logons (Azure or Okta) and Super User logons will continue to work. Leave it unticked unless you want to require SSO-only sign in.
- Click Save.
Important: Only tick Enforce SSO once you have confirmed SSO is working end to end. If SSO is not yet working, your Admin, Manager, and Respondent users will be locked out of the standard login screen.
6. Test and Final Steps
- Return to Azure and run the Test routine.
- To find your Login URL, open Properties in Azure → copy the User Access URL.
Your SAML SSO setup is now complete.
Comments
0 comments
Please sign in to leave a comment.