← Archive

Connecting an internal Snipe-IT instance to Entra ID via an Entra Application Proxy (for SCIM, SAML, and External Access)

Archived post · originally published · may be out of date

Docker Containers & Applications · #EntraID #SCIM #Snipe-IT


TL;DR

  1. Deploy an internal Snipe-IT instance with a URL based on an external domain that exists within one's Entra ID tenant and make sure that same URL is properly referenced by an internal DNS record
  2. Deploy an Entra Application Proxy via an Entra ID application
  3. Configure Snipe-IT to work with the Entra Application Proxy
  4. Configure Snipe-IT to work with SCIM
  5. Configure Snipe-IT to work with SAML (for SSO)
  6. ???
  7. Profit!

Introduction

I recently had the opportunity to deploy a brand new instance of Snipe-IT which means the company I work for is evolving from an Excel spreadsheet for managing assets to a proper asset management solution. However I knew that in order to make this Snipe-IT deployment successful, I had to make it an effortless experience for the technicians using it as otherwise there would be no buy-in and then instead of having an outdated spreadsheet, we would then have an outdated Snipe-IT instance. Normally deploying a new internal application would mean spinning up a server/container, configuring it with LDAP and handing it off, but I wanted a modern, streamlined experience which meant integration with the cloud (SCIM via Entra ID), SSO (SAML) for users, and being able to access Snipe-IT externally (especially on a phone so if a technician forgot their laptop then at least they could use their phone to look up an asset). The solution to make all of this work? An Entra Application Proxy.

Utilizing an Entra Application Proxy

If you never heard of an Entra Application Proxy before, it is a locally hosted agent that provides the ability to publish an internally self-hosted application to the M365 portal (so it becomes externally available) while being able to integrate with Entra ID with both SCIM and SAML. Microsoft's own documentation has an excellent overview of what an Entra Application Proxy is. Stated differently, with the use of an Entra Application Proxy a locally hosted Snipe-IT instance can connect and sync users with Entra ID (SCIM), utilize quality of life features such as SSO (SAML), and is externally accessible through M365. I should clarify what I mean by "externally accessible", as what I mean is that a user can access the internal application through the M365 web portal by signing in with their Microsoft account (and being subject to any M365 security policies that are in place such as MFA, conditional access policies, etc.).

Why use SCIM?

This next section is optional reading but I figured I would explain why we would want to integrate Snipe-IT with SCIM instead of utilizing LDAP. If you are unsure of what SCIM is (System for Cross-Domain Identity Management), it is similar to LDAP in which it is an identity management protocol to sync users to your application of choice (in our case Snipe-IT) except it is significantly more straightforward and easier to use than LDAP.

SCIM has the following advantages over LDAP in which it requires no services accounts to manage, no certificates to deal with, and there is no server that Snipe-IT must be pointed to. In contrast to LDAP, you simply point your Entra ID SCIM application to your Snipe-IT instance (with a URL and API key) and SCIM will automatically push the selected users to Snipe-IT (no configuration on Snipe-IT required). In terms of choosing which users are synced to Snipe-IT, access is managed through the easy to use Entra ID web portal by selecting the groups (or individual users) of your choice instead of messing around with LDAP filters and what not. Finally when utilizing SCIM, an Entra ID application is created and that same application can be used to deploy a SAML configuration to Snipe-IT for SSO functionality. The only real benefit that LDAP provides over SCIM in the context of Snipe-IT, is if you wish to sync users within a certain OU to a specific Snipe-IT location automatically.

Deployment

Prerequisites

  1. Microsoft Entra ID P1 or P2 licenses for the users syncing to and accessing Snipe-IT.

  2. A server that already has a Microsoft Entra private network connector installed on it (as this will be used by the Entra Application Proxy).

  3. A self-hosted Snipe-IT instance.

    • For ease of deployment, make sure the local Snipe-IT instance URL points to an external domain name that is currently within your Entra ID tenant (for example, https://snipe-it.YOURCOMPANY.com) and not an internal domain (such as https://snipe-it.YOURCOMPANY.local). The reason why, is so that the Entra Application Proxy does not need to redirect URLs when connecting to the local Snipe-IT instance and it is also a cleaner user experience as well (as there is only one URL for both internal and external use):
    • You need to sign into your Snipe-IT instance as a super user and create an API Key (which you will use later on during the SCIM section):
      • As the super user select your signed in username, then select Manage API keys, and then create an API key (make sure to save the generatedPersonal Access Token for later):
Snipe-IT API 01 Snipe-IT API 02 Snipe-IT API 03 Snipe-IT API 04

Creating a DNS Entry

If you have not done so already, create an internal DNS entry within your internal environment that references your Snipe-IT instance. If your environment lacks a proper forward lookup zone for your external domain (as was the case for me), what you will do is create a new forward lookup zone that only references the Snipe-IT instance and its subdomain. In the future you can clean up your DNS zone so that a proper forward lookup zone exists that references the entire external domain (with proper records pointing to the various resources) instead of just the Snipe-IT subdomain.

In my environment, we are utilizing Active Directory for DNS management (which I assume is the case for most people):

  1. Launch DNS Manager, navigate to your DNS server of choice, right click Forward Lookup Zones and then select New Zone: Snipe-IT DNS 01

  2. Create a new primary zone based off the full DNS name of your Snipe-IT instance utilizing the default settings -> for example SNIPE-IT.YOURDOMAIN.COM:

Snipe-IT DNS 02 Snipe-IT DNS 03 Snipe-IT DNS 04 Snipe-IT DNS 05 Snipe-IT DNS 06
  1. After the zone has been created, enter into it and create a new A record (blank) that references the IP of the Snipe-IT instance:
Snipe-IT DNS 07 Snipe-IT DNS 08 Snipe-IT DNS 09
  1. Finally test to see that the newly created DNS entry properly routes to Snipe-IT's internal IP address:
Snipe-IT DNS 10

Creating an Entra ID Application (and configuring the Entra ID App Proxy)

The first step required to connect Entra ID with a local Snipe-IT instance is to create an Entra ID Application (which will be used for all three functionalities used by Snipe-IT which includes SCIM, SAML, and external access).

  1. From the Entra ID admin center, navigate to Enterprise Applications under Applications located under Identity, and then select New application:
Snipe-IT Entra App 01 Snipe-IT Entra App 02
  1. Next we will select Add an on-premises application and from the next page we will configure the Entra ID App Proxy settings for your Snipe-IT instance:
Snipe-IT Entra App 03
  1. On the next page, fill out the following details:
    • Name -> name of the Entra ID Application (can be anything)
    • Internal Url -> the internal URL of your Snipe-IT host
    • External Url -> the external URL of your Snipe-IT host (which should match the Internal Url) and if you have added your external domain to M365, then it will appear here as an option
    • Pre Authentication -> select pass through
    • Everything else leave default (including the advanced options)
    • Make note of the CNAME DNS entry and add the CNAME entry to your domain registrar
Snipe-IT Entra App 04
  1. Once completed, select create and from here, make sure to assign some test users to the newly created application under Users and groups:
Snipe-IT Entra App 05
  1. From here, you can now test if your Entra Application Proxy is working by navigating to Snipe-IT from an external location and using a test account that has access to the application. If successful, M365 will require the user to sign-in with their Microsoft account and then will be greeted to the Snipe-IT sign in page after a quick redirection (however, the user will be unable to sign into Snipe-IT as their account is not currently syncing to Snipe-IT via SCIM).

Provisioning SCIM

The next step will be configuring SCIM so Snipe-IT can sync users from Entra ID:

  1. From the newly created application, select Provisioning, and then select Provisioning again:
Snipe-IT SCIM 01 Snipe-IT SCIM 02
  1. For provisioning mode we will select automatic:
    • Under Admin Credentials we will:
      • Supply your Snipe-IT instance url appended with the following -> /scim/v2/?aadOptscim062020 so the url will look like https://SNIPE-IT.YOURDOMAIN.COM/scim/v2/?aadOptscim062020
      • For the Secret Token, supply the previously created Personal Access Token (API Key)
      • Finally, select Test Connection and if everything is properly configured, then you will be greeted with a success message
Snipe-IT SCIM 03 Snipe-IT SCIM 05 Snipe-IT SCIM 04 Snipe-IT SCIM 07 Snipe-IT SCIM 06
  1. Finally, you can go back to the provisioning Overview and start provisioning users:
    1. You have the option of syncing all groups and users or a select group of users/groups -> in my case I only selected a handful of users and groups (these users and groups are the same from the previous step).
    2. Then go back to provisioning page and then what you can do is test SCIM functionality first before provisioning all users and groups:
      1. Select Provision on demand then select a test user/group, and then select provision.
      2. Confirm within Snipe-IT that the provisioned user/group has shown up within the console under users.
    3. Go back to Overview and select start provisionng to provision all of your users and groups -> confirm results within Snipe-IT again:
Snipe-IT SCIM 08

Provisioning SAML (SSO)

The final step, but also the easiest, is configuring your Snipe-IT instance to work with SAML which means when a Entra ID user attempts to sign into Snipe-IT then their login will be SSO:

  1. Sign into your Snipe-IT instance, navigate to the admin section (the gear box) signed as a super user, select SAML, turn on SAML enabled, and then scroll to the bottom of the page to save:
Snipe-IT SAML 01 Snipe-IT SAML 02 Snipe-IT SAML 10
  1. Next, on the same page, select Download Metadata, and then save this file for the next step:
Snipe-IT SAML 04
  1. From here, go back to your Entra ID Snipe-IT application (created from the previous steps), select Single sign-on, select the SAML option, and then from here select Upload metadata file (supply the file from the previous step):

Snipe-IT SAML 05 Snipe-IT SAML 06

  1. Before saving, confirm that the SAML information in the Identifier (Entity ID), Reply URL (Assertion Consumer Service URL), and Logout Url (Optional) fields matches what is found in your Snipe-IT instance on the Update SAML settings page:
Snipe-IT SAML 07 Snipe-IT SAML 10
  1. Save the SAML configuration in your Entra ID application, scroll down to the App Federation Metadata Url section, copy the URL, and then paste it into the SAML IdP Metadata field within the Update SAML settings in your Snipe-IT instance before saving the configuration:
Snipe-IT SAML 11 Snipe-IT SAML 12
* Add the following value under `SAML Custom Settings`:
	* `retrieveParametersFromServer=true` (required to enable SAML SLO Service for Entra ID).
* And finally, enable the following two settings before saving the page:
	* `SAML Single Log Out` and `SAML Force Login`.
  1. If properly configured, you can test SSO functionality by navigating to your Snipe-IT's URL with a user that has access to the application (and has been provisioned to it via SCIM). How it will work is that the user navigates to the Snipe-IT url, then the user account will automatically sign into the application via SSO if configured correctly.

Conclusion

By following this guide, you now have a Snipe-IT instance that is:

The practical impacts of these changes is now Snipe-IT is easily accessible within your environment which should lead to a greater adoption of the application from users and technicians alike. The best way to make people actually use an application is to make it easy as possible to use which was the intended goal of this article. Now that Snipe-IT has been properly configured, your company can finally migrate away from that messy spreadsheet!