Configure Microsoft Entra SAML for SSO
Connect a Microsoft Entra enterprise application to Azion as the identity provider of your account, so users sign in with their Entra identity.
You can make a Microsoft Entra SAML application the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Entra corporate identity and no separate Azion password. The work alternates between the Microsoft Entra admin center and Azion Console. For the Azion side alone, or for an Open ID provider, refer to Configure an identity provider for SSO.
Prerequisites
- An account with Enterprise or Mission-Critical support.
- Administrator access to the Microsoft Entra account.
- Access to Azion Console as an Account owner. To sign in, refer to Access Azion Console.
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to Manage users.
Create the SAML app in Microsoft Entra
Microsoft Entra requires an identifier and a reply URL before it saves the SAML configuration. Use https://sso.azion.com for both now, and replace them with the Azion values later.
To create the application in the Microsoft Entra admin center:
- Go to the Microsoft Entra admin center.
- In the menu, select Applications > Enterprise Applications.
- Select New Application. The page lists gallery applications and an option to create your own.
- Select Create your own application.
- Enter a name for the application. For example:
Azion IdP integration. - (Optional) Enter a description.
- Select Integrate any other application you don’t find in the gallery (Non-gallery).
- Select Create.
- In the new application, select Single sign-on.
- Select the SAML card. The Basic SAML Configuration form opens.
- In Identifier (Entity ID), enter
https://sso.azion.com. - In Reply URL (Assertion Consumer Service URL), enter
https://sso.azion.com. - Select Save. The application page opens.
- In the SAML Certificates section, select Download Certificate (Base64).
You now hold the certificate file and the SAML values of the application for the Azion form.
Create the identity provider in Azion Console
The Create Identity Provider form takes the Microsoft Entra values. Azion then generates the values that Microsoft Entra needs back.
To create the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
Select Add Identity Provider. In Select the Identity Provider, select SAML.
In the General section, enter a Name. For example: Microsoft Entra IdP integration.
In the SAML Configuration section, fill in Identity provider’s Entity ID URI and Sign-in URL with the values of the Microsoft Entra application.
In X-509 Certificate, paste the downloaded certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- tags.
In the Identity Providers list, select the identity provider. In Edit Identity Provider, copy Assertion Consumer Service URL, Service Provider’s Entity ID URI, and Sign-in URL.
The identity provider appears in the Identity Providers list. Do not set it as active until the Microsoft Entra application carries the Azion values.
Complete the SAML app in Microsoft Entra
The Azion values replace the temporary https://sso.azion.com entries. The application also must identify users by email and sign both the response and the assertion.
To finish the application in the Microsoft Entra admin center:
- In the Microsoft Entra admin center, open the application and select Single sign-on.
- In the Basic SAML Configuration box, select Edit.
- In Identifier (Entity ID), paste the Service Provider’s Entity ID URI.
- In Reply URL (Assertion Consumer Service URL), paste the Assertion Consumer Service URL.
- In Sign on URL, paste the Sign-in URL.
- Select Save.
- In the Attributes & Claims box, select Edit.
- In Unique User Identifier, set
user.primaryauthoritativeemail. The email address becomes the user identifier. - In the SAML Certificates box, under Token signing certificate, select Edit.
- In Signing Options, select Sign SAML response and assertion.
- Select Save.
The Microsoft Entra application points at Azion and identifies each user by email.
Assign users in Microsoft Entra
After the SAML settings are saved, add the people who sign in to Azion to the application, one by one or as groups.
To assign users in the Microsoft Entra admin center:
- In the application menu, select Users and groups.
- Add the users and groups that sign in to Azion.
The assigned users and groups can reach the application. To create and update Azion users from Microsoft Entra instead, refer to Provision Microsoft Entra users with SCIM.
Set the identity provider as active
To activate the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
In the row of the identity provider, select Set as active.
Every user of the account, except the Account owner, signs in to Azion Console through Microsoft Entra. While Microsoft Entra is the IdP, it verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.