Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

Setup Shopify Non-Plus Admin SSO with Microsoft Entra ID (Azure AD) as IDP


In this guide, you'll learn how to set up SSO into your Shopify Non-Plus admin using Microsoft Entra ID (Azure AD) Credentials. Get deep visibility, dynamic access restrictions, active threat detection, and granular access control on your Shopify store. Our Shopify CASB Solution allows you to secure your Shopify Admin by configuring IP Restrictions, Device Restrictions, and Country Restrictions features. Implementing Shopify SSO with Microsoft Entra allows users to access Shopify using their Entra ID credentials while maintaining strict security controls.


Note: If you want to set up Shopify SSO with Microsoft Entra ID for your Shopify stores, follow the instructions in this setup guide.


Step 1: Sign up with miniOrange CASB Dashboard

  • Log in to the Cloud Access Security Broker (CASB) with your email and password.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID -login to dashboard | microsoft entra ID sso shopify

  • After logging in, navigate to the Authentication Source in the left sidebar.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- authentication source | shopify sso with entra

  • This will display a list of all existing authentication sources configured in the CASB dashboard. Click on Add New to create a new one.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- add new | configure Shopify into Microsoft Entra ID

  • This will open the configuration screen for the Authentication Source. Enter the Authentication Source Name and click Download Metadata.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID - enter authentication source | entra sso with shopify

Step 2: Setup Microsoft Entra ID (Azure AD) as IDP

  • Sign in to Microsoft Entra ID (Azure AD) and search for Enterprise Applications, as shown below.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- login to azure ad | entra sso with shopify

  • Click on the New Application button.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click on new application | microsoft entra sso shopify

  • Click on the Create your own application button.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-create your own | shopify microsoft sso

  • This will open the configuration menu. Enter a name for your application and click the Create button.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click create | integrate shopify plus entra

  • Once the application is successfully created, you will be redirected to this screen. Click on the Set up single sign-on button.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- set sso | auto sign in Shopify with Microsoft Entra accounts

  • On the next screen, select the SAML option.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- click saml | shopify basic saml configuration

  • Here, you will find an Upload Metadata option, as shown in the image. Click on it and upload the file you downloaded in Step 1.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- upload metadata | integrate shopify plus entra

  • After the file is successfully uploaded, you will see a confirmation screen stating that your IDP configurations for SAML have been imported successfully. Click the Save button to finalize the settings.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- click save | shopify sso with microsoft entra

  • Now, navigate to the Attributes & Claims section and click on Edit.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click edit | shopify plus sso microsoft entra

  • Click on the Add a Group Claim option. A window will appear—select All Groups and then click Save.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click save | sso shopify for microsoft entra

  • Now, return to the Single Sign-On Configuration screen and copy the App Federation Metadata URL, as shown in the image.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-app url | configure entra with shopify sso

  • Return to the CASB Dashboard on the Authentication screen, as shown in Step 1, and click on the Upload Metadata option.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-casb dashboard | connect Microsoft Entra ID and Shopify

  • Select Import Format as URL, paste the URL copied from Azure AD, and click Import.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-import format | shopify microsoft entra sso

  • A prompt will appear confirming that the metadata has been uploaded successfully. Click Save to finalize the configuration.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- click save | entra single sign on shopify

  • Now, return to Azure, navigate to the Users and Groups section, and click on Add User/Group.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-go to users | shopify plus sso microsoft entra

  • Click on Users, as shown in the image, then select the users from the list. The selected users will appear on the right side. Finally, click Save.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click users | microsoft entra sso shopify

  • Once the users are selected, click the Assign button at the bottom left corner.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click assign | entra sso with shopify

  • The selected users for this application will now be displayed as shown below.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-select user | integrate shopify plus entra

  • Now, return to the CASB Dashboard and click on Edit Application.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-edit app | shopify entra single sign on

  • Click on the Test Connection button, as shown below.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-test connection | integrate shopify with Entra ID

  • You will be redirected to the Azure Sign-In screen. Enter the credentials for the user added in the previous steps.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- azure sign in | shopify sso with microsoft entra ID

  • After successful authentication, you will see a screen displaying Test Connection Details. On the left side, you will find attribute keys, and on the right side, their corresponding values. The values marked 1 and 2 will be used in later configuration steps for one-to-one or many-to-one mappings.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-test connection | auto sign-in to Shopify with Microsoft

Step 3: Configure Shopify App in CASB

  • Now , navigate to the Applications section from the sidebar, go to Shopify, and click on Configure.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click configure | entra sso with shopify plus

  • In this section, open the Authentication Source dropdown, select the authentication source you created earlier, and click Save and Next.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID-click save | configure Shopify into Microsoft Entra ID

  • Enter the Application Name and your Store Domain. For the Attribute Key, refer to the values from Step 2.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID- attribute key | shopify microsoft entra sso

  • In the next step, you have two options:


    1. One-to-One Mappings: Choose this option if you want to map a single user from your IAM (Identity and Access Management) system to a single Shopify store admin user. This ensures that only the designated IAM user has access to the Shopify admin account.

    2. Many-to-One Mappings: Choose this option if you need to map multiple IAM users to a single Shopify store admin user. This is useful when multiple team members need to share the same Shopify admin account while maintaining authentication through IAM.




    One to One Mappings :

    • For One-to-One Mapping, enter the Attribute Key’s Name for the email address from the second field as shown in Step 2.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID-second field | Microsoft Entra SSO integration with Shopify


    Many to One Mappings :

    • For Many-to-One Mapping, enter the Attribute Key’s Name for group identifier from the first field as shown in Step 2.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID | shopify entra single sign on

  • Follow the guidelines below for the configurations and click Save:
    • Enable CASB: Turn this on if you want to enforce restriction policies on your Shopify Store Admin.
    • Enable Auditing: Enable this option to track policy breaches in the Shopify Store Admin (this requires CASB to be enabled).
    • Enable Multistaff: Activate this if you are using Many-to-Many Mappings.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID | shopify microsoft entra ID sso

Step 4: User based mapping

  • In the next configuration step, you will map users based on one of the following options:

    One to One Mappings :

    • Click on Add New, as shown in the image.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID | microsoft entra sso shopify

    • In the Group Configuration section, fill in the details as shown in the image and click Save:
      • Group Name: Enter the email address of the user.
      • Group Description: Enter the description of the group.
      • Policy: Select the required policy. If you are using SSO only, choose Default.
      Shopify Non-Plus Admin SSO with Microsoft Entra ID | shopify microsoft entra ID sso

    • Once the user is successfully created, you will see it listed on the left-hand section. Now, to map this user with Shopify user credentials, click on the Add User button.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID | auto sign in Shopify with Microsoft Entra accounts

    • For mapping the user, follow the details below and click Save Configuration:
      • In the IAM Email dropdown, select the user created in the previous step.
      • Enter the Shopify Email Address for the user.
      • Enter the Shopify Password for the user.
      Shopify Non-Plus Admin SSO with Microsoft Entra ID | Microsoft Entra ID connect with Shopify


    Many to One Mappings

    • Click on Add New, as shown in the image.
    • Shopify Non-Plus Admin SSO with Microsoft Entra ID | microsoft entra sso shopify

    • In the Group Configuration section, fill in the details as shown in the image and click Save:
      • Group Name: Enter the group's ObjectId value, which can be taken from the Test Connection in Step 2.
      • Group Description: Enter the Name of the group.
      • Policy: Select the required policy. If you are using SSO only, choose Default.
      Shopify Non-Plus Admin SSO with Microsoft Entra ID | shopify sso configure with entra

    • To map the user group, follow the details below and click Save Configuration:
      • In the IAM Email dropdown, select the group created in the previous step.
      • Enter the Shopify Email Address for the user group.
      • Enter the Shopify Password for the user group.
      Shopify Non-Plus Admin SSO with Microsoft Entra ID | Microsoft Entra ID connect with Shopify

  • Now that the Single Sign-On (SSO) configuration on the Admin side is complete, you will need the SSO URL, as shown in the image. This URL must be configured in the miniOrange CASB extension.
  • Shopify Non-Plus Admin SSO with Microsoft Entra ID | entra sso with shopify plus

  • Now, we will proceed with the User Onboarding Process. Follow this guide to complete the setup.

Not able to configure or test Shopify Non-Plus Admin SSO using Microsoft Entra ID (Azure AD)?
For this, you need to Contact us or email us at proxysupport@xecurify.com and we'll help you setting it up in no time.


External References

Single Sign-On (SSO) for Shopify End Users

If you want to use Shopify SSO with Microsoft Entra for end users or consumers, then you can enable it to streamline login access. Set up secure authentication for your store using this comprehensive guide - Configure Shopify SSO with Entra ID.


miniOrange CASB offers a wide variety of security features with flexible scalability, all available at the most affordable price to all types of businesses. Start by signing up now!


Request a Free Demo!

  

 Thank you for your response. We will get back to you soon.

Please enter your enterprise email-id.

miniOrange CASB solutions making it affordable for organizations