User Guide

Configuring Single Sign-On on Microsoft Entra ID

For Microsoft Entra ID, you can use a directory for SAML configuration. Specify the users and groups to be allowed to use SAML-based login.

1. Creating an enterprise application

1Create an enterprise application.

See Creating an Enterprise Application.

2On the left pane, click [Single sign-on], and for "Select a single sign-on method", click [SAML].

Web browser screen illustration

3Click [Edit] for "Basic SAML Configuration".

Web browser screen illustration

4Configure the following settings as shown below:

Item name on Microsoft Entra ID

Value to be specified

Identifier (Entity ID)

Copy the Entity ID from "SAML Coordination Settings" in your "Tenant Information" at this site, and then paste it into this field.

Reply URL (Assertion Consumer Service URL)

Copy the Reply URL (Assertion Consumer Service URL) from "SAML Coordination Settings" in your "Tenant Information" at this site, and then paste it into this field.

Logout Url (Optional)

Copy the Logout Url from "SAML Coordination Settings" in your "Tenant Information" at this site, and then paste it into this field.

Others

(Omissible)

5Click [Save].

Web browser screen illustration

6Configure attributes and claims.

Proceed to "2. Configuring attributes and caims".

2. Configuring attributes and claims

1Click [Edit] for "Attributes & Claims".

Web browser screen illustration

2Click [Unique User identifier (Name ID)].

Web browser screen illustration

3From the "Source attribute" drop-down list, select "user.mail", and then click [Save].

Web browser screen illustration

4Configure whether or not to synchronize a user's first and last names.

To synchronize a user's first and last names during single sign-on, proceed to "If a User's First and Last Names are to be Synchronized". For not synchronizing, proceed to "If a User's First and Last Names are not to be synchronized".

If a User's First and Last Names are to be Synchronized

  1. Check that the following given name and surname claims are configured as additional requests.

    Web browser screen illustration

    Claim name

    Type

    Value

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

    SAML

    user.givenname

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

    SAML

    user.surname

  2. If they are not configured, click [Add new claim].

    Otherwise, proceed to step 3.

    Web browser screen illustration
  3. Add the given name as shown in the table below and save it.

    Web browser screen illustration

    Item name on Microsoft Entra ID

    Value

    Name

    givenname

    Namespace

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims

    Source

    Attribute

    Source attribute

    user.givenname

  4. Add the surname as shown in the table below and save it.

    Web browser screen illustration

    Item name on Microsoft Entra ID

    Value

    Name

    surname

    Namespace

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims

    Source

    Attribute

    Source attribute

    user.surnname

  5. Configure SAML coordination.

    Proceed to "3. Configuring SAML Coordination”.

If a User's First and Last Names are not to be Synchronized

  1. Check that the following given name and surname claims are configured as additional requests.

    Web browser screen illustration

    Claim name

    Type

    Value

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname

    SAML

    user.givenname

    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

    SAML

    user.surname

  2. If they are configured, delete the settings.

    If they are not configured, proceed to the next step.

  3. Configure SAML coordination.

    Proceed to "3. Configuring SAML Coordination".

3. Configuring SAML Coordination

1On "SAML Certificates", click [Download] for "Federation Metadata XML".

Web browser screen illustration

2Open "SAML Coordination Settings" of your "Tenant Info" at this site on a different screen of your web browser.

3Click [Set as Metadata].

4Click [Select File], and then upload the XML file downloaded on step 1.

5After completing step 4, click [Test].

Web browser screen illustration

6Configure user access to the enterprise application.

Proceed to "4. Configuring user access to an enterprise application".

4. Configuring user access to an enterprise application

Configuring this allows users in the Microsoft Entra ID directory to use SAML-based log in.

To give all users access:

1On the left pane, click [Properties].

2Set "Assignment required?" to [No], and then click [Save].

Web browser screen illustration

To give specific users access:

1On the left pane, click [Users and groups].

2Click [Add user/group] to specify the users or group to which they belong to be allowed to use SAML-based login.

Web browser screen illustration

3Configure SAML Coordination Settings at this site.

Proceed to Configuring SAML Coordination Settings at This Site.