PlatoForms User Guide
Ctrl+K
  • Form Builder

    Creating an Online Form for an Existing PDF

  • Custom Domain

    With Builder you can build three types of forms: online web forms, online PDF forms, and master forms.

  • Master Form Builder

    you will arrive at the Form Builder. On the form Builder, there are three main sections:

Set up single sign-on with Microsoft Entra ID

PlatoForms connects to Microsoft Entra ID (formerly Azure AD) with OpenID Connect or SAML 2.0. OpenID Connect uses an app registration; SAML 2.0 uses an enterprise application and gives members a tile in My Apps.

For an overview of the Single Sign-On page, see Single sign-on (SSO).

Before you begin

  • You are an Entra administrator who can register applications.
  • In PlatoForms, you are the team owner or a member with the Manage members access.
  • In PlatoForms, open your team menu and select Single Sign-On. On the Connection tab, pick Microsoft Entra ID and the protocol you prefer. Keep this page open: it shows the values Entra needs, each with a Copy button.

Option 1: OpenID Connect

In the Microsoft Entra admin center

  1. Go to Identity > Applications > App registrations and click New registration.

  2. Enter a name, for example PlatoForms. Under Supported account types, select Accounts in this organizational directory only.

  3. Under Redirect URI, choose the platform Web and paste the Sign-in redirect URI from PlatoForms. Click Register.

  4. On the Overview page, copy the Application (client) ID and the Directory (tenant) ID.

  5. Go to Certificates & secrets, click New client secret, and copy the secret Value at once. It is shown only once.

    Note

    Copy the Value of the secret, not the Secret ID. Note the expiry date: when the secret expires, sign-in stops until you paste a new one in PlatoForms.

  6. Under API permissions, the default User.Read is enough. Click Grant admin consent so members do not see a consent prompt.

In PlatoForms

  1. Under 3. Values from your identity provider, enter the Issuer URL: https://login.microsoftonline.com/your-tenant-id/v2.0, with your Directory (tenant) ID in place of your-tenant-id.

  2. Paste the Application (client) ID as the Client ID, and the secret Value as the Client secret.

  3. Click Save connection.

Option 2: SAML 2.0

In the Microsoft Entra admin center

  1. Go to Identity > Applications > Enterprise applications and click New application, then Create your own application.

  2. Enter a name, for example PlatoForms, select Integrate any other application you don’t find in the gallery, and click Create.

  3. Open Single sign-on and select SAML.

  4. Edit Basic SAML Configuration:

    • Identifier (Entity ID): the Entity ID from PlatoForms.
    • Reply URL (Assertion Consumer Service URL): the ACS URL from PlatoForms.
    • Sign on URL (optional): the Start URL from PlatoForms.

    Click Save.

  5. Leave Attributes & Claims at the defaults. PlatoForms recognises the email, given name and surname claims Entra sends when you pick Microsoft Entra ID as the provider.

  6. Under SAML Certificates, copy the App Federation Metadata Url.

  7. Under Users and groups, assign the people or groups who may sign in.

In PlatoForms

  1. Under 3. Values from your identity provider, paste the App Federation Metadata Url into Metadata URL and click Load from metadata. PlatoForms fills in the entity ID, the sign-on URL and the signing certificate.

  2. Check the values and click Save connection.

Verify your domain, test and turn on

  1. On the Email domains tab, add your company domain, create the TXT record PlatoForms shows at your DNS provider, and click Verify.

  2. In the status card, click Test connection. A window signs you in through Entra ID and shows the email, name and claim names PlatoForms received.

  3. Click Turn on single sign-on.

Members can now click SSO on the PlatoForms login page, open the start URL, or use the PlatoForms tile in My Apps. See Sign-in rules to require single sign-on or to let new members join automatically.

Good to know

  • Users without a mailbox: when Entra sends no email claim, PlatoForms uses the user principal name as the email address. It must be on one of your verified domains.
  • Guest users: a guest’s address is usually on another domain, so the sign-in is refused unless you verify that domain too.

Troubleshooting

What you see What to check
AADSTS50011 The redirect URI or reply URL in Entra differs from the value on the PlatoForms page.
AADSTS700016, or “Invalid audience” The client ID or the entity ID does not match.
AADSTS50105 The user is not assigned to the enterprise application.
“The identity provider returned a token we could not verify.” The client secret has expired, or the Secret ID was pasted instead of the Value.
“The identity provider sent an email at @example.com, which is not one of your verified domains.” The account’s email or user principal name is on a domain you have not verified.
Is the content helpful?