Step 1: Create the Enterprise Application in Entra ID
In Entra ID, create a new SAML enterprise application for PainChek (or edit an existing template).
Step 2: Configure Basic SAML Settings
In Single sign-on → SAML Configuration, set:
| Entra ID Field | Value | Notes |
|---|---|---|
| Identifier (Entity ID) |
Your Unique PainChek ACS URL, e.g. https://prod.ap.painchek.com/api/sso/acs/UNIQUEID/ |
Same URL as Reply URL |
| Reply URL (ACS URL) | Same as above | Provided by PainChek per-tenant |
| Sign-on URL Asia Pacific | Prod Asia Pacific: https://prod.ap.painchek.com/account/login/ | Fixed Value |
| Sign-on URL Europe | Prod Europe: https://prod.eu.painchek.com/account/login/ | Fixed Value |
| Sign-on URL North America | Prod North America: https://prod.na.painchek.com/account/login/ | Fixed Value |
| Sign-on URL UAT | https://ua.ap.painchek.com/account/login/ | Fixed Value |
| Relay State Asia Pacific | Prod Asia Pacific: https://prod.ap.painchek.com/cloud-portal/dashboard/ | Fixed value |
| Relay State Europe | Prod Europe: https://prod.eu.painchek.com/cloud-portal/dashboard/ | Fixed value |
| Relay State North America | Prod North America: https://prod.na.painchek.com/cloud-portal/dashboard/ | Fixed value |
| Relay State UAT | UAT: https://ua.ap.painchek.com/cloud-portal/dashboard/ | Fixed value |
| Logout URL | — | Leave blank |
Step 3: Configure User Attributes & Claims
Set up the following claims (from your Entra ID enterprise application → Single sign-on → User Attributes & Claims):
| PainChek Claim | Entra ID Source Attribute |
|---|---|
| user.mail | |
| FirstName | user.givenname |
| LastName | user.surname |
| Unique User Identifier | user.mail |
| IDPGroupIds | user.groups |
Note: The above fields are case sensitive.
For the IDPGroupIds claim specifically, when you add/edit it as a group claim (not a plain attribute), you'll be prompted for which groups to emit and in what format:
- Select Security groups (or "Groups assigned to the application" — see Step 4 below for why this matters).
- Set the Source attribute to
sAMAccountName(fallback: Group ID ifsAMAccountNameisn't usable in your tenant). - Confirm the claim name resolves to exactly
IDPGroupIds(case-sensitive) once saved — it will display asuser.groupsin the Attributes & Claims summary screen regardless of which source attribute you picked underneath.
If starting from an existing template, edit rather than duplicate claims: match the claim name PainChek expects, clear the Namespace field, and set the correct source attribute.
Step 4: Set the SAML Signing Option
Under SAML Certificates, set Signing Option to Sign SAML Response (not just the assertion). PainChek requires the whole response to be signed, not just the assertion inside it.
Step 5: Create Entra ID Security Groups for PainChek Roles/Facilities
Create one security group per role and a group for each Facility you need.
For example:
PainChek_User
PainChek_Admin
PainChek_License Admin
PainChek_Facility1
PainChek Facility2
- In the Entra admin center, go to Identity → Groups → All groups → New group.
- Set Group type to Security.
- Give it a clear, consistent name (this name isn't sent to PainChek if you're using
sAMAccountName/Group ID as the source — only the identifier is — so naming is for your own admin sanity, not for PainChek matching). - Add members directly, or better, add other existing groups as members if you already manage role assignment elsewhere.
- Repeat for each role/Facility.
Step 5: Provide PainChek with the Group Names and Metadata URL
Once all the above steps have been completed, send an email to integrations-ap@painchek.com (Asia Pacific and North America) or integrations-eu@painchek.com (for Europe).
Once confirmed that it's set up by PainChek, run a test sign-in.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Groups not mapping in PainChek | Wrong source attribute on the group claim | Confirm IDPGroupIds contains UUIDs, not display names — if you see names, the source attribute is wrong (should be sAMAccountName or Group ID) |
| User not recognised / NameID mismatch | UPN/email sent doesn't match a PainChek user record | Confirm the identifier PainChek receives matches an existing PainChek user exactly |
| Signature validation errors | Response signing mismatch | Confirm "Sign SAML Response" is set (not "Sign assertion" only), and that the certificate pasted into PainChek matches Entra's current signing certificate |