---
title: "Configuring SAML 2.0 Application for Microsoft Entra ID"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35366790/Configuring%20SAML%202.0%20Application%20for%20Microsoft%20Entra%20ID"
format: markdown
---
<span style="color: #000000">Before you configure the SAML federation for Microsoft Entra ID (Active Directory), ensure that you have completed the following:</span>

- [*<span style="color: #000000">Selected a domain and a protocol</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35398160)
- [*<span style="color: #000000">Generated the audience keys</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367311)

> ⚠️ **Note**
> ⚠️ 
> ⚠️ Ensure that you have the required privileges to create and manage a SAML 2.0 application/federation in Microsoft Entra.

# Creating an Enterprise Application

1. <span style="color: #000000">Log in to the Azure portal as an administrator.</span>
2. <span style="color: #000000">Click </span>**<span style="color: #000000">Azure Active Directory</span>** from the Azure services menu.  
  
> Macro (inline-media-image)

  
**Image**: The *Azure Services* menu. This menu displays available services availoablew visa Azure.
3. In the left pane, click **Enterprise Application**.
4. On the **Enterprise Application** page, click **New Application**.  
  
> Macro (inline-media-image)

  
**Image**: How to add a new application by clicking **+ New application**.
5. On the **Browse Microsoft Entra Gallery** page, click **Create your own application**.  
  
> Macro (inline-media-image)

  
**Image**: Click **+ Create your own application **to create your application. .
6. On the **Create your own application** page, complete the following:
  - Enter a name for your application
  - Select the **Integrate any other application you don’t find in the gallery**** (non-gallery)** option.
  - Click **Create**.

> Macro (inline-media-image)

  
**Image**: The *Create your own application* page sdisplaying where to add your name and selecting the radial button to   
integrate any other application in the gallery.  


1. <span style="color: #000000">Assign users and groups to the application you just created. For information, refer to Microsoft Azure documentation at </span>[<span style="color: #000000">https://docs.microsoft.com/en-us/azure/</span>](https://docs.microsoft.com/en-us/azure/)<span style="color: #000000">.</span>

# <span style="color: #000000">Enabling Single Sign-On</span>

1. In the left pane of the application you created, click **Single sign-on** to open the **Single sign-on** pane for editing.
2. Choose the **SAML** option to open the **SAML-based Sign-On** page.
  **Image**: the *Single sign-on* pane, showing how to add a SAML-based sign-on.
3. In the **Set Up Single Sign-On with SAML** section, complete the applicable steps. For information, click **configuration guide **on the Azure portal for more information.
  Image: The *Set Up Single Sign-On with SAML* section, and how to edit the configuration.
4. In step 1, the **Basic SAML Configuration** section, click **Edit** and complete the following:
  - **Identifier (Entity ID)**: <span style="color: #000000">Enter the Audience URI that you copied when generating the audience keys</span>.
  - **Reply URL (Assertion Consumer Service URL**): <span style="color: #000000">Enter the </span>**<span style="color: #000000">HUB ACS URL</span>**<span style="color: #000000"> that you copied when generating the audience keys</span>*<span style="color: #000000">.</span>*
  - **<span style="color: #000000">Sign on URL</span>**<span style="color: #000000">: Enter the same value that you used in the </span>**<span style="color: #000000">Reply URL (Assertion Consumer Service URL)</span>**<span style="color: #000000"> field.</span>  
<span style="color: #000000">*The subjectNameID in the SAML assertion must be the user’s email address, and the email address must have a domain name that matches the domain for which the federation is being configured*</span>**<span style="color: #000000">*.*</span>**
5. In step 2, the **User attributes and claims** section, click **Edit.**
6. In the **User Attributes & Claims** dialog, c<span style="color: #000000">lick </span>**<span style="color: #000000">Add a group claim</span>**<span style="color: #000000">, as shown below:</span>  
  
> Macro (inline-media-image)

  
**<span style="color: #000000">Image</span>**<span style="color: #000000">: The </span>*<span style="color: #000000">User Attributes & Claims</span>*<span style="color: #000000"> dialog. </span>**<span style="color: #000000">Click + Add a group claim</span>**<span style="color: #000000"> to add an attrivbute ns claim.</span>
  
7. <span style="color: #000000">In the </span>**<span style="color: #000000">Group Claims</span>**<span style="color: #000000"> dialog, complete the following to configure groups that should be included in the token:</span>
  1. **<span style="color: #000000">Which groups associated with the user should be returned in the claim</span>**<span style="color: #000000">: Select</span>**<span style="color: #000000"> Security groups.</span>**
  2. **<span style="color: #000000">Source attribute</span>**<span style="color: #000000">: Choose </span>**<span style="color: #000000">Group ID</span>**<span style="color: #000000"> from the drop-down menu.</span>
  3. <span style="color: #000000">In the </span>**<span style="color: #000000">Advanced options</span>**<span style="color: #000000"> section, select the </span>**<span style="color: #000000">Customize the name of the group claim</span>**<span style="color: #000000"> check box.</span>
  4. **<span style="color: #000000">Name (required)</span>**<span style="color: #000000">: Enter </span>**<span style="color: #000000">groups</span>**<span style="color: #000000">.</span>

  
> Macro (inline-media-image)

  
**Image**: In the *Group Claims* dialog, select the Security groups radial button.

1. <span style="color: #000000">Click </span>**<span style="color: #000000">Save</span>**<span style="color: #000000">.</span>
2. In step 3, the **SAML Signing Certificate** section:
  1. <span style="color: #000000">Download the </span>**<span style="color: #000000">Certificate(Base64)</span>**<span style="color: #000000"> and save it for later.</span>
3. <span style="color: #000000">In section </span>**<span style="color: #000000">4: Set up "<</span>*****<span style="color: #000000">your application</span>*****<span style="color: #000000">></span>**<span style="color: #000000">," section:</span>
  1. <span style="color: #000000">Copy the </span>**<span style="color: #000000">Login URI</span>**<span style="color: #000000"> and </span>**<span style="color: #000000">Azure AD Identifier</span>**<span style="color: #000000"> and save them for later.</span>

# <span style="color: #000000">Configuring SAML Application</span>

1. <span style="color: #000000">Log in to the Infoblox SSO Portal.</span>
2. <span style="color: #000000">In the Infoblox SSO Portal, go to </span>**<span style="color: #000000">Authentication</span>**<span style="color: #000000"> ></span>**<span style="color: #000000"> </span>****<span style="color: #000000">3rd Party IdP</span>**<span style="color: #000000">, click </span>**<span style="color: #000000">Configure Azure SAML</span>**<span style="color: #000000"> and then complete the following:</span>
  1. **<span style="color: #000000">Login URL</span>**<span style="color: #000000">: Enter or paste the Login URI you copied from the Azure </span>**<span style="color: #000000">Set up <</span>*****<span style="color: #000000">your application</span>*****<span style="color: #000000">></span>**<span style="color: #000000"> section.</span>
  2. **<span style="color: #000000">Azure AD Identifier</span>**<span style="color: #000000">: Enter or paste the Azure AD Identifier you copied from the </span>**<span style="color: #000000">Set up <</span>*****<span style="color: #000000">your application</span>*****<span style="color: #000000">></span>**<span style="color: #000000"> section.</span>
  3. **<span style="color: #000000">Signature Certificate</span>**<span style="color: #000000">: Paste the certificate you copied from the Azure </span>**<span style="color: #000000">SAML Signing Certificate</span>**<span style="color: #000000"> section. The SSO Portal supports Base64 certificates with the following file extensions: </span>*<span style="color: #000000">.crt</span>*<span style="color: #000000">, </span>*<span style="color: #000000">.pem</span>*<span style="color: #000000">, and </span>*<span style="color: #000000">.ca-bundle</span>*<span style="color: #000000">.</span>
3. <span style="color: #000000">Click </span>**<span style="color: #000000">Save and Close</span>**<span style="color: #000000">.</span>
4. <span style="color: #000000">After you have configured the SAML application, you can complete the following configuration:</span>
  - [*<span style="color: #000000">Mapping User Groups</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463665)
  - [*<span style="color: #000000">Testing 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367251)
  - [*<span style="color: #000000">Activating 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35463635)
5. <span style="color: #000000">You can also perform the following after you set up 3rd party IdP authentication:</span>
  - [*<span style="color: #000000">Deactivating 3rd Party IdP Authentication</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35464005)
  - [*<span style="color: #000000">Resetting 3rd Party IdP</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367439)
  - [*<span style="color: #000000">Adding an IdP Application to Microsoft Azure</span>*](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneCloud/pages/35367488)