---
name: azion-configure-microsoft-entra-saml-for-sso
description: >-
  Connect a Microsoft Entra enterprise application to Azion as the identity provider of your account, so users sign in with their Entra identity.
---

# Configure Microsoft Entra SAML for SSO

You can make a Microsoft Entra SAML application the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Entra corporate identity and no separate Azion password. The work alternates between the Microsoft Entra admin center and Azion Console. For the Azion side alone, or for an Open ID provider, refer to [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso/).

---

## Prerequisites

- An account with **Enterprise** or **Mission-Critical** support.
- Administrator access to the Microsoft Entra account.
- Access to Azion Console as an **Account owner**. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to [Manage users](/en/documentation/guides/platform/account-and-billing/users-management/).

---

## Create the SAML app in Microsoft Entra

Microsoft Entra requires an identifier and a reply URL before it saves the SAML configuration. Use `https://sso.azion.com` for both now, and replace them with the Azion values later.

To create the application in the Microsoft Entra admin center:

1. Go to the [Microsoft Entra admin center](https://entra.microsoft.com/).
2. In the menu, select **Applications** > **Enterprise Applications**.
3. Select **New Application**. The page lists gallery applications and an option to create your own.
4. Select **Create your own application**.
5. Enter a name for the application. For example: `Azion IdP integration`.
6. (Optional) Enter a description.
7. Select **Integrate any other application you don't find in the gallery (Non-gallery)**.
8. Select **Create**.
9. In the new application, select **Single sign-on**.
10. Select the **SAML** card. The **Basic SAML Configuration** form opens.
11. In **Identifier (Entity ID)**, enter `https://sso.azion.com`.
12. In **Reply URL (Assertion Consumer Service URL)**, enter `https://sso.azion.com`.
13. Select **Save**. The application page opens.
14. In the **SAML Certificates** section, select **Download Certificate (Base64)**.

You now hold the certificate file and the SAML values of the application for the Azion form.

---

## Create the identity provider in Azion Console

The **Create Identity Provider** form takes the Microsoft Entra values. Azion then generates the values that Microsoft Entra needs back.

To create the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Open the create form**

   Select **Add Identity Provider**. In **Select the Identity Provider**, select *SAML*.

3. **Name the identity provider**

   In the **General** section, enter a **Name**. For example: `Microsoft Entra IdP integration`.

4. **Enter the Microsoft Entra values**

   In the **SAML Configuration** section, fill in **Identity provider's Entity ID URI** and **Sign-in URL** with the values of the Microsoft Entra application.

5. **Add the certificate**

   In **X-509 Certificate**, paste the downloaded certificate, including the `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags.

6. **Select Save**

7. **Copy the Azion values**

   In the **Identity Providers** list, select the identity provider. In **Edit Identity Provider**, copy **Assertion Consumer Service URL**, **Service Provider's Entity ID URI**, and **Sign-in URL**.

The identity provider appears in the **Identity Providers** list. Do not set it as active until the Microsoft Entra application carries the Azion values.

---

## Complete the SAML app in Microsoft Entra

The Azion values replace the temporary `https://sso.azion.com` entries. The application also must identify users by email and sign both the response and the assertion.

To finish the application in the Microsoft Entra admin center:

1. In the [Microsoft Entra admin center](https://entra.microsoft.com/), open the application and select **Single sign-on**.
2. In the **Basic SAML Configuration** box, select **Edit**.
3. In **Identifier (Entity ID)**, paste the **Service Provider's Entity ID URI**.
4. In **Reply URL (Assertion Consumer Service URL)**, paste the **Assertion Consumer Service URL**.
5. In **Sign on URL**, paste the **Sign-in URL**.
6. Select **Save**.
7. In the **Attributes & Claims** box, select **Edit**.
8. In **Unique User Identifier**, set `user.primaryauthoritativeemail`. The email address becomes the user identifier.
9. In the **SAML Certificates** box, under **Token signing certificate**, select **Edit**.
10. In **Signing Options**, select **Sign SAML response and assertion**.
11. Select **Save**.

The Microsoft Entra application points at Azion and identifies each user by email.

---

## Assign users in Microsoft Entra

After the SAML settings are saved, add the people who sign in to Azion to the application, one by one or as groups.

To assign users in the Microsoft Entra admin center:

1. In the application menu, select **Users and groups**.
2. Add the users and groups that sign in to Azion.

The assigned users and groups can reach the application. To create and update Azion users from Microsoft Entra instead, refer to [Provision Microsoft Entra users with SCIM](/en/documentation/guides/application-security/access-and-compliance/microsoft-entra-automated-user-provisioning/).

---

## Set the identity provider as active

To activate the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Set the identity provider as active**

   In the row of the identity provider, select **Set as active**.

3. **Select Confirm**

Every user of the account, except the Account owner, signs in to Azion Console through Microsoft Entra. While Microsoft Entra is the IdP, it verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.

---

## Next steps

- [Provision Microsoft Entra users with SCIM](/en/documentation/guides/application-security/access-and-compliance/microsoft-entra-automated-user-provisioning.md): Create, update, and delete Azion users from Microsoft Entra.
- [Configure Google SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-google-saml.md): Use a Google custom SAML app as the IdP instead.
- [Configure Okta SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-okta-saml.md): Use an Okta SAML 2.0 app integration as the IdP instead.
- [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso.md): Add any SAML or Open ID provider in SSO Management.
