---
title: "Using Microsoft Azure AD as the IdP"
canonical: "https://docs.infoblox.com/space/BloxOneCloud/35367279/Using%20Microsoft%20Azure%20AD%20as%20the%20IdP"
format: markdown
---
## <span style="color: #000000">SAML Authentication</span>

<span style="color: #000000">To integrate SAML with Azure AD as the IdP, you must configure Azure AD SSO integration with Azure AD SAML toolkit. For information, refer to the Microsoft documentation. You must also configure SAML2.0 attributes and token claims.</span>

> ⚠️ **Note**
> ⚠️ 
> ⚠️ The Azure AD groups must have **Group ID** format only.

<span style="color: #000000">To configure the SAML2.0 attributes, complete the following:</span>

- Click **Add a group claim** -> **All Groups**, and set **Source Attribute** to **Group ID.**
- Select **Customize the name of the group claim** and set the name to **groups**, and then click **Save**.
- Edit **User Attributes & Claims** to obtain the **NameID**.
- Edit **Unique User Identifier** and choose the appropriate attribute (*user.mail*, or *user.mailnickname*), or transformation, such as **Join** (*user.mailnickname* @ "*azureadinfoblox.com*"). Note that this attribute will be displayed in reports as a username. Therefore, Infoblox recommends that you avoid using persistent or transient identifiers.

<span style="color: #000000">The following table lists the required parameters for a successful integration:</span>

| <span style="color: #000000">**Infoblox Platform Parameter**</span> | <span style="color: #000000">**Description**</span> | <span style="color: #000000">**Usage**</span> |
| --- | --- | --- |
| **<span style="color: #000000">Entity ID</span>**<span style="color: #000000"> (Service Provider)</span> | <span style="color: #000000">The Entity ID is the audience URI for setting up the basic SAML configuration.</span> | - <span style="color: #000000">Copy </span>**<span style="color: #000000">Entry ID</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">SERVICE PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Identifier</span>**<span style="color: #000000"> field on the </span>*<span style="color: #000000">Basic SAML Configuration page</span>*<span style="color: #000000"> in the Azure AD SAML Toolkit SSO configuration.</span> |
| **<span style="color: #000000">Assertion Consumer Service URL</span>**<span style="color: #000000"> (Service Provider)</span> | <span style="color: #000000">The Assertion Consumer Service (ACS) URL directs your IdP where to send the SAML response after authenticating a user. </span> | - <span style="color: #000000">Copy </span>**<span style="color: #000000">Assertion Consumer Service URL</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">SERVICE PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Reply URL</span>**<span style="color: #000000"> field on the </span>*<span style="color: #000000">Basic SAML Configuration page</span>*<span style="color: #000000"> in the Azure AD SAML Toolkit SSO configuration.</span> |
| **<span style="color: #000000">Metadata URL</span>**<span style="color: #000000"> (IdP)</span> | <span style="color: #000000">The IdP Metadata URL directs you to the XML file that contains the IdP information you need to set up the connection with the IdP. You do not need to enter other details separately if you can obtain the XML file.</span> | - <span style="color: #000000">Copy the </span>**<span style="color: #000000">App </span>****<span style="color: #000000">Federation Metadata Url</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">SAML Signing Certificate</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">SAML-based Sign-on</span>*<span style="color: #000000"> page in the Azure AD SAML Toolkit SSO configuration.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Metadata URL</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">IDENTITY PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |
| **<span style="color: #000000">Issuer</span>**<span style="color: #000000"> (IdP)</span> | <span style="color: #000000">The IdP Issuer is the URL that defines the unique identifier for your SAML application.</span> | - <span style="color: #000000">Copy the </span>**<span style="color: #000000">Azure AD I</span>****<span style="color: #000000">dentifier </span>**<span style="color: #000000">from the </span>*<span style="color: #000000">Set up Azure AD SAML Toolkit</span>*<span style="color: #000000"> page in the Azure AD SAML Toolkit SSO configuration.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Issuer</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">IDENTITY PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |
| **<span style="color: #000000">SSO URL</span>**<span style="color: #000000"> (IdP)</span> | <span style="color: #000000">The IdP SSO URL redirects the service provider to Azure AD to authenticate and sign on the user.</span> | - <span style="color: #000000">Copy the </span>**<span style="color: #000000">Login URL</span>**<span style="color: #000000"> from the </span>*<span style="color: #000000">Set up Azure AD SAML Toolkit</span>*<span style="color: #000000"> page in the Azure AD SAML Toolkit SSO configuration.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">SSO URL</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">IDENTITY PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |
| **<span style="color: #000000">Signing Certificate</span>**<span style="color: #000000"> (IdP)</span> | <span style="color: #000000">The IdP Signing Certificate ensures that data is coming from the expected IdP and service provider. The certificate is used to sign SAML requests, responses, and assertions from the service to relying applications.</span> | - <span style="color: #000000">Download the </span>**<span style="color: #000000">Certificate Base64</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">SAML Signing Certificate</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">SAML-based Sign-on</span>*<span style="color: #000000"> page in the Azure AD SAML Toolkit SSO configuration.</span>
- <span style="color: #000000">In the </span>**<span style="color: #000000">IDENTITY PROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal, click </span>**<span style="color: #000000">Select file</span>**<span style="color: #000000"> for </span>**<span style="color: #000000">Signing Certificate</span>**<span style="color: #000000"> to locate the downloaded certificate.</span> |

## <span style="color: #000000">OpenID Connect Authentication</span>

<span style="color: #000000">To integrate OpenID Connect with Azure AD as the IdP, you must configure and register a new OpenID Connect application in Azure AD. For information, refer to the Microsoft documentation.</span>

<span style="color: #000000">To include user-related information such as e-mail address, you must configure specific claims to be passed within the ID token. </span>To configure token claims, complete the following:

1. Navigate to **Token Configuration** in the left panel.
2. Configure email claim: Click **Add optional claim** -> select** ID** → select **Check email** -> **Turn on the Microsoft Graph email permission** > click **Add**.
3. Configure groups claim: Click **Add groups claim** -> select **Security Group**s -> select **ID** for all kinds > click **Add**.

For users to log in, they must be assigned to the application. To configure user and group assignments, complete the following:

1. Navigate to **Enterprise Applications** -> *<application name>* -> **Users and Groups**:
2. Click **Add User** -> select *<users and/or groups>* -> click **Selec**t -> click **Assign**.

To obtain **Client ID**, complete the following:

- Navigate to **Overview** -> **Essentials** -> **Locate Application (client) ID**

<span style="color: #000000">The following table lists the required parameters for a successful integration:</span>

| <span style="color: #000000">**Parameter**</span> | <span style="color: #000000">**Description**</span> | <span style="color: #000000">**Usage**</span> |
| --- | --- | --- |
| **<span style="color: #000000">Login Redirect URI</span>**<span style="color: #000000"> (Client)</span> | <span style="color: #000000">The Login Redirect URI determines </span><span style="color: #000000">where the authorization server redirects the user once the application successfully authorizes and grants an authorization code or access token.</span> | - <span style="color: #000000">Copy </span>**<span style="color: #000000">Login Redirect URI</span>**<span style="color: #000000"> from the </span>**<span style="color: #000000">CLIENT DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Add Redirect URI</span>**<span style="color: #000000"> for the </span>**<span style="color: #000000">Web</span>**<span style="color: #000000"> platform on the OpenID Connect </span>*<span style="color: #000000">Application</span>*<span style="color: #000000"> page in the Azure AD App Registration configuration.</span> |
| **<span style="color: #000000">Client ID</span>**<span style="color: #000000"> (Client)</span> | <span style="color: #000000">The Client ID is the ID for logging in to the IdP client.</span> | - <span style="color: #000000">Copy </span>**<span style="color: #000000">Application (client) ID </span>**<span style="color: #000000">from the </span>**<span style="color: #000000">Essentials </span>**<span style="color: #000000">section of the OpenID Connect </span>*<span style="color: #000000">Application</span>*<span style="color: #000000"> page in the Azure AD App Registration configuration.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Client ID</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">CLIENT DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |
| **<span style="color: #000000">Client Secret</span>**<span style="color: #000000"> (Client)</span> | <span style="color: #000000">The Client Secret is the password for logging in to the IdP client.</span> | - <span style="color: #000000">In the </span>**<span style="color: #000000">Certificates & Secrets </span>**<span style="color: #000000">section of the OpenID Connect </span>*<span style="color: #000000">Application</span>*<span style="color: #000000"> page in the Azure AD App Registration configuration, create a new client secret and copy it.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Client Secret</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">CLIENT DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |
| **<span style="color: #000000">Issuer</span>**<span style="color: #000000"> (IdP)</span> | <span style="color: #000000">The Issuer is the URL that defines the unique identifier for your OpenID Connect application.</span> | - <span style="color: #000000">In the OpenID Connect application, click </span>**<span style="color: #000000">Endpoints</span>**<span style="color: #000000"> and request for the OpenID Connect metadata file. Download the JSON file and locate the </span>**<span style="color: #000000">Issuer</span>**<span style="color: #000000"> field in the file.</span>
- <span style="color: #000000">Enter the copied value in the </span>**<span style="color: #000000">Issuer</span>**<span style="color: #000000"> field in the </span>**<span style="color: #000000">IDENTITY ROVIDER DETAILS</span>**<span style="color: #000000"> section of the </span>*<span style="color: #000000">Create Authentication Profile</span>*<span style="color: #000000"> dialog on the Infoblox Portal.</span> |