---
name: azion-configure-an-identity-provider-for-sso
description: >-
  Add a SAML or Open ID identity provider in SSO Management and set it as active, so account users sign in to Azion Console with single sign-on.
---

# Configure an identity provider for SSO

You can connect an external identity provider (IdP) to your account in **SSO Management** of Azion Console, so account users sign in with their corporate credentials. This page covers the Azion side for any provider. For the provider side of Google, Microsoft Entra, or Okta, refer to [Configure Google SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-google-saml/), [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml/), or [Configure Okta SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-okta-saml/). For how single sign-on works, refer to [Single Sign-On](/en/documentation/fundamentals/single-sign-on/).

---

## Prerequisites

- An Enterprise plan for the account.
- Access to Azion Console as an **Account owner**. Only an Account owner chooses between the Azion login and an external IdP for the users of the account. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- An application for Azion in your IdP, and the values it issues for the protocol you choose.

---

## Add the identity provider

The **Create Identity Provider** form takes one protocol, *SAML* or *Open ID*, and the values your IdP issued for it.

To add the identity provider in Azion Console:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**. The **Identity Providers** list opens.

2. **Open the create form**

   Select **Add Identity Provider**. The **Create Identity Provider** form opens.

3. **Choose the protocol**

   In **Select the Identity Provider**, select *SAML* or *Open ID*.

4. **Name the identity provider**

   In the **General** section, enter a **Name**. For example: `Corporate IdP`.

5. **Enter the provider values**

   For *SAML*, fill in the **SAML Configuration** section: **Identity provider's Entity ID URI**, **Sign-in URL**, and **X-509 Certificate**.

   For *Open ID*, fill in the **Open ID Provider Configuration** section: **Client ID**, **Client Secret**, **Authorization URL**, **Token URL**, **UserInfo URL**, **Scopes**, and **Response Mode**.

6. **Select Save**

The identity provider appears in the **Identity Providers** list, with its **Name** and **Protocol**. It is not in use until you set it as active.

---

## Copy the Azion values to your IdP

A SAML application in your IdP needs two values that Azion generates for the identity provider: **Service Provider's Entity ID URI** and **Assertion Consumer Service URL**. Both are in the **SAML Configuration** section of the saved identity provider.

To copy the values:

1. **Open the identity provider**

   In the **Identity Providers** list, select the identity provider. The **Edit Identity Provider** form opens.

2. **Copy the values**

   Copy **Service Provider's Entity ID URI** and **Assertion Consumer Service URL**, and enter them in your IdP application.

Your IdP application now points at Azion. The provider pages for [Google](/en/documentation/guides/application-security/access-and-compliance/sso-google-saml/), [Microsoft Entra](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml/), and [Okta](/en/documentation/guides/application-security/access-and-compliance/sso-okta-saml/) name the field that takes each value.

---

## Set the identity provider as active

Activate the identity provider only after your IdP application carries the Azion values. Every user of the account must also exist in Azion with the same email, or the sign-in fails. For more information, refer to [Manage users](/en/documentation/guides/platform/account-and-billing/users-management/).

To activate the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Set the identity provider as active**

   In the row of the identity provider, select **Set as active**.

3. **Select Confirm**

Every user of the account, except the Account owner, signs in to Azion Console through the IdP. While the IdP is active, the IdP verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.

---

## Next steps

- [Configure Google SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-google-saml.md): Connect a Google custom SAML app to the account.
- [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml.md): Connect a Microsoft Entra enterprise application to the account.
- [Configure Okta SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-okta-saml.md): Connect an Okta SAML 2.0 app integration to the account.
- [Single Sign-On](/en/documentation/fundamentals/single-sign-on.md): Read how single sign-on works for an Azion account.
