> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On with Microsoft Entra ID (SAML)

> Configure SAML-based SSO between Microsoft Entra ID and Iru Endpoint. Set up the enterprise application in Entra and map user attributes for login.

### About Microsoft Entra ID SAML Integration

Microsoft Entra ID SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with Microsoft Entra ID for users accessing Iru Endpoint through their Microsoft Entra ID credentials.

#### How It Works

When users attempt to access Iru Endpoint, they're redirected to Microsoft Entra ID for authentication. After successful authentication, Microsoft Entra ID sends a SAML assertion back to Iru Endpoint, which validates the user's identity and grants access. SSO can be used for [Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) sign-in and for [Require Authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment).

<Note>
  Note: Microsoft Entra ID [is the new name](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/new-name) for Azure AD (Azure Active Directory)
</Note>

<Tabs>
  <Tab title="Iru Web App Configuration">
    ### Setting Up the SAML Connection

    <Note>
      You'll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Microsoft Entra ID. After copying the Entity ID and ACS URL, switch to the [**Microsoft Entra ID Configuration**](#microsoft-entra-id-configuration) tab and continue with [**Configuring Microsoft Entra ID Application**](#configuring-microsoft-entra-id-application).
    </Note>

    <Steps>
      <Step title="Navigate to the Account Menu Button">
        In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
      </Step>

      <Step title="Access Authentication Settings">
        Click the **Access** option in the menu.

        <Frame>
          <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
        </Frame>
      </Step>

      <Step title="Select Admin and Authentication">
        Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**.
      </Step>

      <Step title="Add Authentication Method">
        Click **+ Authentication method**.
      </Step>

      <Step title="Enter Display Name">
        Enter a display name for the SSO Connection.
      </Step>

      <Step title="Select Authentication Method">
        Select **SAML** for the Authentication method.
      </Step>

      <Step title="Create Connection">
        Click **Create**.
      </Step>

      <Step title="Configuration Information">
        Click **Configuration information** if that section is not already expanded.
      </Step>

      <Step title="Copy Service Provider Entity ID">
        Copy the **Service provider entity ID** into a text document for later use. You'll need this for the Entra ID configuration.
      </Step>

      <Step title="Copy ACS URL">
        Copy the **Assertion consumer service (ACS) URL** into a text document for later use. You'll need this for the Entra ID configuration.

        <Frame>
          <img src="https://mintcdn.com/iru/Qq59wQ8jCPy0XJe9/assets/media/images/iru-support-google-saml_11-08-26.png?fit=max&auto=format&n=Qq59wQ8jCPy0XJe9&q=85&s=7d56d5b22f71fb05dd59c83555c02430" alt="Configuration Information, Service provider entity ID, and Assertion consumer service (ACS) URL" width="2166" height="940" data-path="assets/media/images/iru-support-google-saml_11-08-26.png" />
        </Frame>
      </Step>

      <Step title="Keep Tab Open">
        Keep the Iru Endpoint configuration modal open, then switch to the [**Microsoft Entra ID Configuration**](#microsoft-entra-id-configuration) tab to continue with [**Configuring Microsoft Entra ID Application**](#configuring-microsoft-entra-id-application).
      </Step>
    </Steps>

    ### Configuring Iru Endpoint SAML Connection

    <Note>
      After completing the Microsoft Entra ID configuration, return here to finish [**Configuring Iru Endpoint SAML Connection**](#configuring-iru-endpoint-saml-connection) in Iru Endpoint. You'll need the Single Sign-on URL, IdP Entity ID, and certificate from Microsoft Entra ID.
    </Note>

    <Steps>
      <Step title="Return to Iru Endpoint">
        Go back to the Custom SAML modal in Iru Endpoint.
      </Step>

      <Step title="Configure IdP Attribute">
        Set **IdP attribute** to **Subject**.
      </Step>

      <Step title="Configure Attribute Name">
        Leave **Attribute name** blank.
      </Step>

      <Step title="Configure User Attribute">
        Set **User attribute** to **User Principal Name (UPN)**.
      </Step>

      <Step title="Add IdP Entity ID">
        Paste the **Microsoft Entra Identifier** you copied earlier into the **IdP Entity ID** field.
      </Step>

      <Step title="Add Sign In URL">
        Paste in the **Sign In URL** you copied from Entra ID.
      </Step>

      <Step title="Upload Certificate">
        Upload the **certificate** you downloaded from Entra ID.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-23-01.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=3abe0d549d07a4797c46b99ff1351a24" alt="Iru Endpoint upload certificate from Entra ID" width="1722" height="622" data-path="assets/media/images/entra-saml_11-23-01.png" />
        </Frame>
      </Step>

      <Step title="Set Protocol Binding">
        Set the **Protocol Binding** to **HTTP-POST**.
      </Step>

      <Step title="Set Request Algorithm">
        Ensure that the **Request Algorithm** is set to **RSA-SHA256**.
      </Step>

      <Step title="Set Digest Algorithm">
        Ensure that **Sign Request Algorithm Digest** is set to **SHA256**.
      </Step>

      <Step title="Enable Sign Request">
        Ensure that **Sign Request** is enabled.
      </Step>

      <Step title="Set Response Signature Verification">
        Set the **Response Signature Verification** to **Assertion**.
      </Step>

      <Step title="Set Destination">
        Leave the **Destination** field blank.
      </Step>

      <Step title="Set Allowed Signature Algorithm">
        Set **Allowed Signature Algorithm** to **RSA-SHA256**.
      </Step>

      <Step title="Set Allowed Digest Algorithm">
        Set **Allowed Digest Algorithm** to **SHA256**.
      </Step>

      <Step title="Save Configuration">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-32-41.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=c7370100d7ab5f1d488caabb3ca554d2" alt="Iru Endpoint Save for SAML configuration" width="1720" height="694" data-path="assets/media/images/entra-saml_11-32-41.png" />
        </Frame>
      </Step>
    </Steps>

    ### Allow for Tenant Authentication

    Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

    ### Limit Authentication to Domain

    When configuring the SAML connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains.

    ### Enforcing Single Sign-On

    Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions.

    ## Considerations

    **Security**: Ensure that your Microsoft Entra ID tenant has appropriate security policies configured for SSO authentication.

    **User Management**: Users must exist in both Microsoft Entra ID and Iru Endpoint to successfully authenticate via SSO.

    **Testing**: Always test the SSO integration with a small group of users before rolling out to your entire organization.

    ### Testing the Integration

    <Steps>
      <Step title="Add User to Admin Team">
        Add a user to the **Admin Team** in Iru Endpoint by clicking **New User**.
      </Step>

      <Step title="Fill User Information">
        Fill in all of the corresponding user information. This user must exist in Microsoft Entra ID and must be assigned to the Iru Endpoint SSO app in your Microsoft Entra ID tenant.
      </Step>

      <Step title="Submit User">
        Click **Submit**.
      </Step>

      <Step title="Close Invite Window">
        Once the invite is submitted, close the Invite User window.
      </Step>

      <Step title="Refresh Access Page">
        Refresh the Access page in Iru Endpoint. You should see the user you just added.
      </Step>

      <Step title="Test SSO Login">
        Check the user's email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection.
      </Step>
    </Steps>
  </Tab>

  <Tab title="Microsoft Entra ID Configuration">
    <Note>
      Before starting the Microsoft Entra ID configuration, complete [**Setting Up the SAML Connection**](#setting-up-the-saml-connection) in the [**Iru Web App Configuration**](#iru-web-app-configuration) tab to get the Service Provider Entity ID and ACS URL. You'll need these values to configure the Microsoft Entra ID application.
    </Note>

    ### Configuring Microsoft Entra ID Application

    <Steps>
      <Step title="Access Microsoft Entra Admin Center">
        Sign in to the [Microsoft Entra admin center](https://entra.microsoft.com).
      </Step>

      <Step title="Expand Entra ID Section">
        In the left navigation bar, ensure that the **Entra ID** section is expanded.
      </Step>

      <Step title="Navigate to Applications">
        In the left navigation bar, click **Enterprise apps**.
      </Step>

      <Step title="Create New Application">
        Select **+ New application**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_09-32-53.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=3110cface8a6ba6ea0892706d2ee7440" alt="Entra ID Enterprise apps New application" width="3622" height="1978" data-path="assets/media/images/entra-saml_09-32-53.png" />
        </Frame>
      </Step>

      <Step title="Create Custom Application">
        Select **Create your own application**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_09-35-21.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=f888b9248c8eb6fd752f73de72c29716" alt="Entra ID Create your own application" width="3394" height="1190" data-path="assets/media/images/entra-saml_09-35-21.png" />
        </Frame>
      </Step>

      <Step title="Name the Application">
        Give the application a **name**.
      </Step>

      <Step title="Select Non-Gallery Option">
        Select **Integrate any other application you don't find in the gallery (Non-gallery)**.
      </Step>

      <Step title="Create Application">
        Click **Create**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_09-37-41.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=c330ae2b582893c6ed7808033d32b530" alt="Entra ID Name app Non-gallery Create" width="1124" height="918" data-path="assets/media/images/entra-saml_09-37-41.png" />
        </Frame>
      </Step>

      <Step title="Access Single Sign-On">
        Under **Manage**, select **Single sign-on**.
      </Step>

      <Step title="Select SAML">
        Select the **SAML** tile.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_09-40-52.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=cea5dd96dfcdd40bd8f26bf2fb815fba" alt="Entra ID Single sign-on SAML tile" width="3394" height="2030" data-path="assets/media/images/entra-saml_09-40-52.png" />
        </Frame>
      </Step>

      <Step title="Edit Basic Configuration">
        Click the **Edit** pencil in the Basic SAML configuration box

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_09-43-13.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=259b449cab7d148c120cbd5b03365f54" alt="Entra ID Edit Basic SAML configuration" width="2764" height="2220" data-path="assets/media/images/entra-saml_09-43-13.png" />
        </Frame>
      </Step>

      <Step title="Configure Entity ID">
        Click the Add Identifier link in the Identifier (Entity ID) section. Paste the Entity ID that you copied earlier into the Identifier (Entity ID) field.
      </Step>

      <Step title="Configure Reply URL">
        In the Reply URL (Assertion Consumer Service URL) section, paste the Assertion Consumer Services URL that you copied earlier.
      </Step>

      <Step title="Save Configuration">
        Click **Save**.
      </Step>

      <Step title="Close Configuration">
        Click the **X** at the top right of the pane to close it.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_0-27-34.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=5eca89414d2ed95c54c05717d8462024" alt="Entra ID Identifier and Reply URL Save and close" width="1682" height="1876" data-path="assets/media/images/entra-saml_0-27-34.png" />
        </Frame>
      </Step>

      <Step title="Keep Default Claims">
        Leave the settings in the **Attributes & Claims section** set to their default.
      </Step>

      <Step title="Download Certificate">
        Click **Download** to download the Base 64 certificate in the SAML Certificates section. This certificate will be used in the Custom SAML configuration in Iru Endpoint.
      </Step>

      <Step title="Copy URL">
        In the **Set up \[App Name]** section, copy the Login URL and paste it into a secure text document for later use.
      </Step>

      <Step title="Copy Microsoft Entra Identifier">
        Copy the **Microsoft Entra Identifier** and save it in a text document. You will paste this into the **IdP Entity ID** field in Iru Endpoint. You can find this in the **Overview** section of your application.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_10-32-47.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=b5145304814e64723c07ef114f24ebc3" alt="Entra ID Set up section Login URL and Microsoft Entra Identifier" width="2812" height="2614" data-path="assets/media/images/entra-saml_10-32-47.png" />
        </Frame>
      </Step>

      <Step title="Navigate to App Registrations">
        Go to **App registrations**.
      </Step>

      <Step title="Select Your App">
        Select your newly created app.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_10-43-18.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=6791ce0a76c4dadf8b1bea7189a84788" alt="Entra ID App registrations select your app" width="2496" height="1432" data-path="assets/media/images/entra-saml_10-43-18.png" />
        </Frame>
      </Step>

      <Step title="Navigate to Token Configuration">
        Navigate to the **Token configuration** section under **Manage**.
      </Step>

      <Step title="Add Optional Claims">
        Click **+ Add optional claims**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_10-51-33.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=41e719d9c3d42fce4525af478cd0704d" alt="Entra ID Token configuration Add optional claims" width="2686" height="1744" data-path="assets/media/images/entra-saml_10-51-33.png" />
        </Frame>
      </Step>

      <Step title="Check ID Button">
        Check the **ID** radio button.
      </Step>

      <Step title="Check Acct Box">
        Check the **acct** box.
      </Step>

      <Step title="Check Email Box">
        Check the **email** box.
      </Step>

      <Step title="Check UPN Box">
        Check the **upn** box.
      </Step>

      <Step title="Click Add">
        Click **Add**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_10-54-06.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=b0866fab2e9b1233e3ede973c2fade72" alt="Entra ID Optional claims ID acct email upn Add" width="1136" height="1980" data-path="assets/media/images/entra-saml_10-54-06.png" />
        </Frame>
      </Step>

      <Step title="Accept API Permissions">
        Check the **Turn on the Microsoft Graph email, profile permission (required for claims to appear in token)** box.
      </Step>

      <Step title="Click Add">
        Click **Add**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-11-53.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=41ae2748fe871ff7f1869c3e0793401f" alt="Entra ID Turn on Microsoft Graph email profile permission Add" width="1128" height="434" data-path="assets/media/images/entra-saml_11-11-53.png" />
        </Frame>
      </Step>
    </Steps>

    <Info>
      The Microsoft Entra Identifier is used in the Iru configuration as the IdP Entity ID.
    </Info>

    ### Assigning Users and Groups

    <Steps>
      <Step title="Navigate to App">
        In **Enterprise apps** navigate to your newly created app.
      </Step>

      <Step title="Access Users and Groups">
        Under **Manage**, select **Users and Groups**.
      </Step>

      <Step title="Add User/Group">
        On the menu, select **Add user/group**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-44-49.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=fd4cc7d9d05d4ae90b06d41938c6ec3e" alt="Entra ID Users and Groups Add user or group" width="2904" height="2050" data-path="assets/media/images/entra-saml_11-44-49.png" />
        </Frame>
      </Step>

      <Step title="Select Users and Groups">
        On the **Add Assignment** dialog, select the link under **Users and groups**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-48-33.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=1361e5a43cd64d0172ba67bdfac4d54d" alt="Entra ID Add Assignment Users and groups link" width="2904" height="1204" data-path="assets/media/images/entra-saml_11-48-33.png" />
        </Frame>
      </Step>

      <Step title="Search and Select Users">
        A list of users and security groups is displayed. You can search for a certain user or group, as well as select multiple users and groups that appear in the list.
      </Step>

      <Step title="Confirm Selection">
        After you have selected your users and groups, select **Select**.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-49-38.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=32f4597734ef2b3132a5546eeefe727f" alt="Entra ID Select users and groups then Select" width="2202" height="1108" data-path="assets/media/images/entra-saml_11-49-38.png" />
        </Frame>
      </Step>

      <Step title="Assign Users and Groups">
        Select **Assign** to finish assigning users and groups to the app.

        <Frame>
          <img src="https://mintcdn.com/iru/rJbYmFioHfvuqINA/assets/media/images/entra-saml_11-54-12.png?fit=max&auto=format&n=rJbYmFioHfvuqINA&q=85&s=ed24e34a180f6adb4746cc58552f0ce8" alt="Entra ID Assign to finish assigning users and groups" width="2492" height="1204" data-path="assets/media/images/entra-saml_11-54-12.png" />
        </Frame>
      </Step>

      <Step title="Verify Assignment">
        Confirm that the users and groups you added appear in the **Users and groups** list.

        <Frame>
          <img src="https://mintcdn.com/iru/Gez-fJ-p5uwNt6_O/assets/media/images/entra-saml_11-55-22.png?fit=max&auto=format&n=Gez-fJ-p5uwNt6_O&q=85&s=c598aaf03d4d81b16dac4a4f96ac14df" alt="Entra ID Users and groups list showing assigned users" width="2492" height="1204" data-path="assets/media/images/entra-saml_11-55-22.png" />
        </Frame>
      </Step>

      <Step title="Do Not Require Assignment">
        Alternatively, if you don't want to assign users and groups, you can set the app to not require assignment.
      </Step>

      <Step title="Navigate to Enterprise App">
        Navigate to your newly created app in **Enterprise apps**.
      </Step>

      <Step title="Click Properties">
        Click **Properties** under Manage.
      </Step>

      <Step title="Set Assignment Required">
        Set **Assignment required?** to **No**.
      </Step>

      <Step title="Click Save">
        Click **Save**.

        <Frame>
          <img src="https://mintcdn.com/iru/Gez-fJ-p5uwNt6_O/assets/media/images/entra-saml_11-59-02.png?fit=max&auto=format&n=Gez-fJ-p5uwNt6_O&q=85&s=15c2a308bdd7e1be7dd41f2c5ccf04ae" alt="Entra ID Properties Assignment required No Save" width="2492" height="2082" data-path="assets/media/images/entra-saml_11-59-02.png" />
        </Frame>
      </Step>
    </Steps>

    <Info>
      If you see a message about free tier limitations, it means that a free tier is being used. The Single Sign-On Enterprise App lets you add users (not groups) only.
    </Info>

    <Note>
      After completing the Microsoft Entra ID configuration, return to the **Iru Web App Configuration** tab to finish setting up the SAML connection using the SSO URL, Entity ID, and certificate you copied from Microsoft Entra ID.
    </Note>
  </Tab>
</Tabs>
