This guide explains the steps to configure Microsoft Single Sign-On (SSO) for your organization using Microsoft Entra ID (formerly Azure AD).

Benefits of Microsoft SSO Integration All organization members can enable single sign-on using Microsoft credentials. Centralized user access management via Microsoft Entra ID. Secure access control across all applications. Prerequisites Microsoft Entra ID Premium License (recommended for full functionality) Global Administrator or Application Administrator privileges in Microsoft Entra ID Verified domain ownership in your Microsoft tenant Users with email addresses matching the organization’s domain Organization account already created in the application Organization Owner or Administrator role in the application Setup Steps

  1. Sign in with a Global or Application Administrator Account Navigate to: Identity → Applications → Enterprise applications

Click + New application.

Select Create your own application.

Choose Integrate any other application you don't find in the gallery (Non-gallery).

Enter the application name (e.g., "OrganizationName App SSO").

Click Create.

  1. Configure Single Sign-On In the new enterprise application, go to: Manage → Single sign-on

Select SAML as the SSO method.

In the Basic SAML Configuration section, click Edit.

To obtain the required information, enable SSO from your organization’s settings.

Identifier (Entity ID): Contact your application administrator. Reply URL: Contact your application administrator. Sign-on URL: Automatically generated after SSO setup.

  1. User Attributes & Claims Ensure the following attributes are set in the User Attributes & Claims section:

Claims in Entra ID must exactly match the following values (including additional claims). If not, SSO authentication may fail.

Required Claim:

Unique user identifier (Name ID): SAML user.userprincipalname [nameid-format:emailAddress] Additional Claims:

These should be set automatically, but confirm their presence.

  1. SAML Certificates Record the Thumbprint value (must be provided to the application administrator). Copy the Login URL from the setup section. Save these values for application configuration: Thumbprint/Fingerprint Login URL
  2. Assign Users and Groups Go to: Manage → Users and groups