# SAML v2.0 SSO with Entra ID - Integration Guide

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-field-details-docume" style="margin-left: 36.0pt; border-collapse: collapse; border: none; mso-border-alt: solid #A3A3A3 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm;" summary="" title=""><tbody><tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"><td style="width: 82.95pt; border: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="111">**Field**</td><td style="width: 348.2pt; border: solid #A3A3A3 1.0pt; border-left: none; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="464">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Details</span>**

</td></tr><tr style="mso-yfti-irow: 1;"><td style="width: 84.3pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="112"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Document Type</span>

</td><td style="width: 346.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="462"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">How-To Guide: SSO Integration</span>

</td></tr><tr style="mso-yfti-irow: 2;"><td style="width: 82.95pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="111"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Applies To</span>

</td><td style="width: 353.15pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="471"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Microsoft Entra ID, Any SAML 2.0-compatible SaaS or Third-Party Application</span>

</td></tr><tr style="mso-yfti-irow: 3;"><td style="width: 82.95pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="111"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Audience</span>

</td><td style="width: 348.2pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="464"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">2nd Line / Systems Administrator / IT Engineer</span>

</td></tr><tr><td style="width: 82.95pt; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt;"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Author</span>

</td><td style="width: 348.2pt; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt;"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">AK. Udofeh</span>

</td></tr><tr style="mso-yfti-irow: 4; mso-yfti-lastrow: yes;"><td style="width: 82.95pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="111"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Last Updated</span>

</td><td style="width: 348.2pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="464"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">March 2026</span>

</td></tr></tbody></table>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Overview</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">This article covers how to configure Single Sign-On (SSO) using the SAML 2.0 protocol between Microsoft Entra ID and any third-party or SaaS application that supports SAML for authentication. It is intended for systems administrators who need to integrate enterprise applications with Entra ID to centralise identity management, enforce MFA, and control user access. The guide covers Enterprise Application creation in Entra ID, SAML endpoint configuration, certificate handling, and attribute claim mapping.</span>

<span style="mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> </span>

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">SAML SSO works by delegating authentication to Entra ID as the Identity Provider (IdP). The application (Service Provider / SP) redirects the user to Entra's SAML endpoint, which authenticates the user and returns a signed SAML assertion containing identity attributes. The application validates the assertion signature using Entra's signing certificate and establishes a user session.</span>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Common Failure Points</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Incorrect ACS (Assertion Consumer Service) URL registered in Entra</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Entity ID mismatch between the application and Entra configuration</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Entra signing certificate not imported into the application, or certificate has expired</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Attribute claims not mapping to the fields the application expects</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">SLO (Single Logout) URL misconfigured, causing logout failures</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">User not assigned to the Enterprise Application in Entra</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Before You Start</span>**

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-check-where-you-have" style="margin-left: 36pt; border-collapse: collapse; border: none; width: 95%; height: 189.875px;" summary="" title=""><tbody><tr style="height: 25.3125px;"><td style="width: 50%; border: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 25.3125px;" valign="top" width="367">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Check</span>**

</td><td style="width: 50%; border-top: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-image: initial; border-left: none; padding: 2pt 3pt; height: 25.3125px;" valign="top" width="214">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Where</span>**

</td></tr><tr style="height: 44.3125px;"><td style="width: 50%; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt; height: 44.3125px;" valign="top" width="367"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">You have Global Administrator or Application Administrator rights in Entra ID</span>

</td><td style="width: 50%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 44.3125px;" valign="top" width="214"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra ID &gt; Roles and Administrators</span>

</td></tr><tr style="height: 25.3125px;"><td style="width: 50%; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt; height: 25.3125px;" valign="top" width="367"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">The target application supports SAML 2.0 (not only OIDC)</span>

</td><td style="width: 50%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 25.3125px;" valign="top" width="220"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Application vendor documentation</span>

</td></tr><tr style="height: 25.3125px;"><td style="width: 50%; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt; height: 25.3125px;" valign="top" width="368"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">You have the application's ACS URL, Entity ID, and SLO URL</span>

</td><td style="width: 50%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 25.3125px;" valign="top" width="218"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Application vendor documentation or SP metadata XML</span>

</td></tr><tr style="height: 44.3125px;"><td style="width: 50%; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt; height: 44.3125px;" valign="top" width="367"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Outbound HTTPS (port 443) from the application server to </span><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">login.microsoftonline.com</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"> is permitted</span>

</td><td style="width: 50%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 44.3125px;" valign="top" width="214"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Firewall / network policy</span>

</td></tr><tr style="height: 25.3125px;"><td style="width: 50%; border-right: 1pt solid rgb(163, 163, 163); border-bottom: 1pt solid rgb(163, 163, 163); border-left: 1pt solid rgb(163, 163, 163); border-image: initial; border-top: none; padding: 2pt 3pt; height: 25.3125px;" valign="top" width="367"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">You have admin access to the application's configuration</span>

</td><td style="width: 50%; border-top: none; border-left: none; border-bottom: 1pt solid rgb(163, 163, 163); border-right: 1pt solid rgb(163, 163, 163); padding: 2pt 3pt; height: 25.3125px;" valign="top" width="214"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Application admin console or hosting environment</span>

</td></tr></tbody></table>

<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 1: Create an Enterprise Application in Entra ID</span>

<p class="callout info"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">For SAML SSO, configuration is done through</span><span style="font-size: 12.0pt; font-family: 'Cambria',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Cambria; mso-fareast-language: EN-GB;"> </span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Enterprise Applications, not App Registrations. An App Registration is created automatically in the background.</span></p>

- - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Navigate to </span><span style="font-size: 12pt; color: rgb(53, 152, 219);">[<span style="font-family: 'unset', serif;">portal.azure.com</span>](https://portal.azure.com/)</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> &gt; Entra ID &gt; Enterprise Applications &gt; New application.</span>
    - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Click Create your own application.</span>
    - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Enter a display name (e.g. </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">AppName SAML SSO</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">).</span>
    - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Select "Integrate any other application you don't find in the gallery".</span>
    - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Click Create.</span>

<p class="callout success"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> You will be taken to the application overview page.</span></p>

<span style="mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> </span>

<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 2: Configure SAML Settings</span>

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Inside the Enterprise Application, go to Single Sign-On &gt; SAML.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Click Edit on the Basic SAML Configuration panel.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Fill in the following fields using values from your application's documentation or SP metadata:</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Identifier (Entity ID)\*: <span style="font-family: pplxSansMono, serif; color: rgb(53, 152, 219);">[https://app.yourdomain.com/saml/metadata](https://app.yourdomain.com/saml/metadata)</span></span>
    
    <span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">(this is a Unique URI that identifies the Service Provider)</span>
    
    <span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Reply URL </span><span style="color: rgb(221, 221, 221); font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Oxygen, Ubuntu, Roboto, Cantarell, 'Fira Sans', 'Droid Sans', 'Helvetica Neue', sans-serif; font-size: 0.94em; font-weight: 400;">(Assertion Consumer Service URL)\*: <span style="font-family: pplxSansMono, serif; color: rgb(53, 152, 219);">[https://app.yourdomain.com/saml/acs](https://app.yourdomain.com/saml/acs)</span></span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">(this is where Entra ID posts the signed SAML assertion)</span>
    
    <div class="azc-required-balloon fxc-base azc-control azc-dockedballoon-requiredwidget azc-dockedballoon-required" data-control="true"><div aria-hidden="true" class="azc-dockedballoon-anchor"><div class="azc-required-anchor"><svg focusable="false" height="6px" role="presentation" viewbox="0 0 6 6" width="6px" xlink="http://www.w3.org/1999/xlink" xmlns:svg="http://www.w3.org/2000/svg"><g></g></svg></div></div></div><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Sign-on URL (optional): <span style="font-family: pplxSansMono, serif; color: rgb(53, 152, 219);">[https://app.yourdomain.com/login](https://app.yourdomain.com/login)</span></span>
    
    <span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">(SP-initiated login entry point)</span>
    
    <span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Logout URL (optional): <span style="font-family: pplxSansMono, serif; color: rgb(53, 152, 219);">[https://app.yourdomain.com/saml/sls](https://app.yourdomain.com/saml/sls)</span></span>
    
    <span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">(SP's Single Logout endpoint)</span>


<p class="callout info"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">If the application provides a metadata XML URL (e.g<span style="color: rgb(53, 152, 219);">. </span></span><span style="font-size: 12pt; color: rgb(53, 152, 219);">[<span style="font-family: pplxSansMono, serif;">https://app.yourdomain.com/saml/metadata</span>](https://app.yourdomain.com/saml/metadata)</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"><span style="color: rgb(53, 152, 219);">), </span>Entra can import these values automatically — click Upload metadata file at the top of the Basic SAML Configuration panel.</span></p>

<p class="callout info"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Click Save.</span></p>

<span style="mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> </span>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 3: Download the Entra Signing Certificate</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Still in the SAML configuration view, scroll to Section 3 &gt; SAML Certificates.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Download Certificate (Base64) &gt; this produces a </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">.cer</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> or </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">.pem</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> file.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Open the file in a text editor. The content between </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">-----BEGIN CERTIFICATE-----</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> and </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">-----END CERTIFICATE-----</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> is the base64-encoded certificate value you will need for the application.</span>


<p class="callout warning"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Store a copy of this certificate securely. If Entra's signing certificate is rotated (e.g. on expiry), the application will fail to validate assertions until the new certificate is imported.</span></p>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 4: Collect IdP Configuration Values</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In the SAML configuration page, note the following values in the "Set up &lt;app name&gt;":</span>

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-value-description-lo" style="margin-left: 36.0pt; border-collapse: collapse; border: none; mso-border-alt: solid #A3A3A3 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm;" summary="" title=""><tbody><tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"><td style="width: 98.65pt; border: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="132"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Value</span>

</td><td style="width: 336.55pt; border: solid #A3A3A3 1.0pt; border-left: none; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="449"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Description</span>

</td></tr><tr style="mso-yfti-irow: 1;"><td style="width: 98.65pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="132"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Login URL</span>

</td><td style="width: 336.55pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="449"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra's SAML SSO endpoint - set as the IdP SSO URL in the application</span>

</td></tr><tr style="mso-yfti-irow: 2;"><td style="width: 98.65pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="132"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Logout URL</span>

</td><td style="width: 336.55pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="449"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra's SAML SLO endpoint - set as the IdP SLO URL in the application</span>

</td></tr><tr style="mso-yfti-irow: 3;"><td style="width: 98.65pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="132"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra ID Identifier</span>

</td><td style="width: 336.55pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="449"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra's Entity ID - set as the IdP Entity ID in the application</span>

</td></tr><tr style="mso-yfti-irow: 4; mso-yfti-lastrow: yes;"><td style="width: 98.65pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="132"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Certificate (Base64)</span>

</td><td style="width: 336.55pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="449"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Signing certificate from Step 3 - used by the application to validate assertions</span>

</td></tr></tbody></table>

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Alternatively, download the Federation Metadata XML from the same section - many applications can import this file directly to auto-populate all IdP settings.</span>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 5: Configure Attribute Claims in Entra</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">By default, Entra sends a standard set of SAML attribute claims. Verify these match what the application expects:</span>

- - <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In the Enterprise Application SAML configuration, click Edit on Section 2 - Attributes &amp; Claims.</span>

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> The default claims sent by Entra are:</span>

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-claim-name-value-ema" style="margin-left: 36.0pt; border-collapse: collapse; border: none; mso-border-alt: solid #A3A3A3 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm;" summary="" title=""><tbody><tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"><td style="width: 73.8pt; border: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="98">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Claim Name</span>**

</td><td style="width: 111.9pt; border: solid #A3A3A3 1.0pt; border-left: none; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="149">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Value</span>**

</td></tr><tr style="mso-yfti-irow: 1;"><td style="width: 75.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="100"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">emailaddress</span>

</td><td style="width: 110.5pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="147"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">user.mail</span>

</td></tr><tr style="mso-yfti-irow: 2;"><td style="width: 73.8pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="98"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">givenname</span>

</td><td style="width: 111.9pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="149"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">user.givenname</span>

</td></tr><tr style="mso-yfti-irow: 3;"><td style="width: 73.8pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="98"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">surname</span>

</td><td style="width: 111.9pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="149"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">user.surname</span>

</td></tr><tr style="mso-yfti-irow: 4; mso-yfti-lastrow: yes;"><td style="width: 73.8pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="98"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">name</span>

</td><td style="width: 116.95pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="156"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">user.userprincipalname</span>

</td></tr></tbody></table>

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">If the application requires different attribute names or additional claims, click Add new claim to add or rename them.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">To include group membership in the assertion (for role mapping), click Add a group claim &gt; select Security groups.</span>

<p class="callout warning"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">By default, Entra sends group</span><span style="font-size: 12.0pt; font-family: 'Cambria',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Cambria; mso-fareast-language: EN-GB;"> </span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Object IDs</span><span style="font-size: 12.0pt; font-family: 'Cambria',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Cambria; mso-fareast-language: EN-GB;"> </span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">(GUIDs) in the group claim, not display names. Configure the application's role mapping to use Object IDs, or change the group claim's source attribute to display names if supported.</span></p>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 6: Restrict Access via Enterprise Application (Recommended)</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In the Enterprise Application, go to Properties.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Set "Assignment required?" to Yes &gt; Save.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Go to Users and groups &gt; Add user/group &gt; assign the relevant users or Entra security groups.</span><p class="callout success">Only assigned users will be permitted to authenticate via SAML SSO. Unassigned users receive an Entra-side access denied error before reaching the application.</p>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Step 7: Configure the Application</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In the Service Provider application, enter the values collected in Step 4 into the application's SAML configuration. The exact setting names vary per application - refer to the application vendor's SAML documentation. The standard SAML parameters are:</span>

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-application-setting-" style="margin-left: 36.0pt; border-collapse: collapse; border: none; mso-border-alt: solid #A3A3A3 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm;" summary="" title=""><tbody><tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Application Setting</span>

</td><td style="width: 289.75pt; border: solid #A3A3A3 1.0pt; border-left: none; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Value to Enter</span>

</td></tr><tr style="mso-yfti-irow: 1;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">IdP Entity ID</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Entra ID Identifier from Step 4</span>

</td></tr><tr style="mso-yfti-irow: 2;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">IdP SSO URL</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Login URL from Step 4</span>

</td></tr><tr style="mso-yfti-irow: 3;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">IdP SLO URL</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Logout URL from Step 4</span>

</td></tr><tr style="mso-yfti-irow: 4;"><td style="width: 106.65pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="142"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">IdP X.509 Certificate</span>

</td><td style="width: 288.3pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="384"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Certificate base64 content from Step 3</span>

</td></tr><tr style="mso-yfti-irow: 5;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">SP Entity ID</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Must match the Identifier (Entity ID) entered in Entra Step 2</span>

</td></tr><tr style="mso-yfti-irow: 6;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">ACS URL</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Must match the Reply URL entered in Entra Step 2</span>

</td></tr><tr style="mso-yfti-irow: 7;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Name ID Format</span>

</td><td style="width: 294.7pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="393"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">emailAddress</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"> or </span><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">persistent</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"> - check application documentation</span>

</td></tr><tr style="mso-yfti-irow: 8; mso-yfti-lastrow: yes;"><td style="width: 105.25pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="140"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Binding</span>

</td><td style="width: 289.75pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="386"><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">HTTP-POST</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"> for ACS; </span><span style="font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">HTTP-Redirect</span><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;"> for AuthnRequest</span>

</td></tr></tbody></table>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">=========================Troubleshooting====================</span>**

<span style="font-size: 18.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">AADSTS750054: SAMLRequest or SAMLResponse must be present as query string parameters</span>

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The application is not correctly forming the SAML AuthnRequest, or the binding type does not match Entra's expectation.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Confirm the application is using HTTP Redirect binding for the AuthnRequest - Entra requires this for SP-initiated flows.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Check the application's SAML configuration for a "request binding" or "binding type" setting and ensure it is set to </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">HTTP-Redirect</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">AADSTS70011: The provided value for the input parameter 'redirect\_uri' is not valid</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The ACS URL registered in Entra does not match the URL the application is posting to.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Retrieve the application's SP metadata from its metadata URL or admin panel.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Compare the </span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">AssertionConsumerService</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> URL in the metadata against the Reply URL (ACS URL) registered in Entra.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Update the Reply URL in Entra to match exactly - including scheme (</span><span style="font-size: 12.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">https://</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">), full path, and no trailing slash.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">AADSTS750057: Invalid SAML response or no SAML response</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The Entity ID in the application does not match what is registered in Entra, or the SAML response is malformed.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Confirm the SP Entity ID configured in the application exactly matches the Identifier (Entity ID) in Entra.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Confirm the IdP Entity ID configured in the application matches the Entra ID Identifier shown in Section 4 of the Entra SAML page.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">These values are case-sensitive and must match character for character.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Assertion signature validation fails / </span><span style="font-size: 18.0pt; font-family: 'pplxSansMono',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Invalid signature</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The X.509 certificate used for validation in the application does not match the current Entra signing certificate, or the certificate has expired.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In the Enterprise Application SAML configuration &gt; Certificates &gt; check the expiry date of the active certificate.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">If expired or rotated, click New Certificate, make it active, and download the new Base64 certificate.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Import the new certificate into the application's SAML configuration.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Restart the application service if required.</span>


<p class="callout warning"><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Entra signing certificates expire every 3 years by default. Set a calendar reminder 60 days before expiry to plan a rotation window.</span></p>

<span style="mso-ascii-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-hansi-font-family: Calibri; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"> </span>

**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Single Logout (SLO) does not work - user remains signed in to Entra after signing out of the application</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The SLO URL is not configured in either Entra or the application, or the binding types do not match.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Confirm the Logout URL field in Entra's Basic SAML Configuration points to the application's SLO endpoint.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Confirm the application's IdP SLO URL is set to the Logout URL shown in Entra Section 4.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Entra uses HTTP Redirect binding for logout requests - confirm the application's SLO endpoint accepts GET/Redirect binding, not only POST.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">User authenticates successfully in Entra but receives an error or no access in the application</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The SAML assertion was accepted, but the user account was provisioned with no role or permissions in the application.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Log in to the application as an administrator.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Assign an appropriate role to the SSO-provisioned user account.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">To automate this for future users, configure a default role for SSO-registered accounts, or implement group-to-role mapping using the group claim configured in Step 6.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Attribute claims are empty or not recognised by the application</span>**

<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">**Cause:** The attribute claim names sent by Entra do not match the names the application is expecting.</span>

**<span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Resolution:</span>**

- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">In Entra → Enterprise Application &gt; Attributes &amp; Claims, note the full claim URI names being sent (e.g. </span><span style="font-size: 12pt; color: rgb(53, 152, 219);">[<span style="font-family: pplxSansMono, serif;">http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress</span>](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)</span><span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;"><span style="color: rgb(53, 152, 219);">)</span>.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Cross-reference these with the application's expected attribute names from the vendor documentation.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Either rename claims in Entra to match the application, or update the application's attribute mapping to match Entra's output.</span>
- <span style="font-size: 12.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Use a SAML tracer browser extension or the application's debug mode to inspect the raw assertion during a test login.</span>


**<span style="font-size: 18.0pt; font-family: 'pplxSerif',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: Calibri; mso-fareast-language: EN-GB;">Expected Outcome</span>**

<table border="1" cellpadding="0" cellspacing="0" class="MsoNormalTable" id="bkmrk-factor-detail-resolu" style="margin-left: 36.0pt; border-collapse: collapse; border: none; mso-border-alt: solid #A3A3A3 1.0pt; mso-yfti-tbllook: 1184; mso-padding-alt: 0cm 0cm 0cm 0cm;" summary="" title=""><tbody><tr style="mso-yfti-irow: 0; mso-yfti-firstrow: yes;"><td style="width: 93.45pt; border: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="125">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Factor</span>**

</td><td style="width: 341.65pt; border: solid #A3A3A3 1.0pt; border-left: none; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="456">**<span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Detail</span>**

</td></tr><tr style="mso-yfti-irow: 1;"><td style="width: 93.45pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="125"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Resolution Time</span>

</td><td style="width: 346.6pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="462"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">45–90 minutes for initial configuration; additional time if attribute mapping requires investigation</span>

</td></tr><tr style="mso-yfti-irow: 2;"><td style="width: 93.45pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="125"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">User Impact</span>

</td><td style="width: 341.65pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="456"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Zero - SAML SSO is additive; existing local accounts remain functional during migration</span>

</td></tr><tr style="mso-yfti-irow: 3;"><td style="width: 93.45pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="125"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Recurrence Risk</span>

</td><td style="width: 341.65pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="456"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Low - primary recurring issue is Entra signing certificate expiry (every 3 years by default)</span>

</td></tr><tr style="mso-yfti-irow: 4; mso-yfti-lastrow: yes;"><td style="width: 93.45pt; border: solid #A3A3A3 1.0pt; border-top: none; mso-border-top-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="125"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Ongoing Maintenance</span>

</td><td style="width: 341.65pt; border-top: none; border-left: none; border-bottom: solid #A3A3A3 1.0pt; border-right: solid #A3A3A3 1.0pt; mso-border-top-alt: solid #A3A3A3 1.0pt; mso-border-left-alt: solid #A3A3A3 1.0pt; padding: 2.0pt 3.0pt 2.0pt 3.0pt;" valign="top" width="456"><span style="font-family: 'pplxSans',serif; mso-fareast-font-family: 'Times New Roman'; mso-bidi-font-family: 'Times New Roman'; mso-fareast-language: EN-GB;">Rotate Entra signing certificate before expiry; manage user access via Enterprise Application assignments</span>

</td></tr></tbody></table>