Skip to main content

Enable SAML Token Encryption for WorkBoard in Microsoft Entra ID

SAML token encryption provides an additional layer of security by ensuring that SAML assertions from Microsoft Entra ID are encrypted befo...

Updated over a week ago

SAML token encryption provides an additional layer of security by ensuring that SAML assertions from Microsoft Entra ID are encrypted before being sent to WorkBoard. This prevents interception of token contents and protects personal and corporate data.

Follow the steps below to upload your WorkBoard-provided encryption certificate and enable token encryption for your Enterprise Application.

Before You start

To complete the configuration, you'll need:

  • Admin access to Microsoft Entra ID

  • The WorkBoard SAML Token Encryption Certificate, provided by the WorkBoard team

  • To contact WorkBoard Support or your assigned WorkBoard representative to finalize the setup

1. Navigate to the WorkBoard enterprise application in your Entra ID

  1. Sign in to the Microsoft Entra Admin Center.

  2. Go to Identity > Applications > Enterprise Applications.

  3. Select your WorkBoard application from the list.

    Screenshot 2025-11-21 at 10.50.41.png

2. Open the Token Encryption Settings

  1. In the left navigation panel, select Security.

  2. Click Token encryption.

  3. You will see the current token encryption status and any existing certificates.

Screenshot 2025-11-21 at 10.55.05.png

3. Upload the WorkBoard Encryption Certificate

  1. Select Import Certificate at the top of the page.

  2. Upload the .cer certificate file provided by the WorkBoard team.

  3. After uploading, select the certificate to Enable it for token encryption.

  4. Confirm that the status updates to Active.

Your screen should now show the enabled certificate with a start date and expiration date.

Screenshot 2025-11-21 at 10.57.13.png

4. Notify WorkBoard to complete the configuration

Once the certificate is enabled in Entra ID:

  1. Contact WorkBoard Support or your WorkBoard Customer team.

  2. Provide confirmation that the encryption certificate has been uploaded and enabled.

  3. WorkBoard will then enable encrypted SAML assertions for your WorkBoard tenant.

    Important: Token encryption will not take effect until WorkBoard completes the configuration on their side.

Need Help?

If you need the encryption certificate or assistance with the setup, please contact [email protected] or your WorkBoard representative.

Did this answer your question?