Skip to main content

Configure Microsoft Entra ID for SSO

How to integrate Microsoft Entra ID with Hyver for SAML-based single sign-on.

Updated over 5 months ago

Overview

This guide walks you through the steps to configure Microsoft Entra ID (formerly Azure AD) for SAML-based single sign-on with Hyver. Once set up, your users can log in using Microsoft credentials, without needing separate Hyver accounts or passwords. 


1. Start in the Azure portal

  1. Open the Azure portal:

  2. Click View under the Manage Microsoft Entra ID tile.


2. Create and configure the application

  1. In the left-hand menu, under Manage, select Enterprise applications.

  2. Click Create your own application.

  3. Choose Integrate any other application you don't find in the gallery.

  4. Name your application and click Create:

  5. Once created, go to Single sign-on and select the SAML tile.


3. Fill in basic SAML configuration

  1. In the Basic SAML Configuration section, click Edit.

  2. Copy the Hyver entity ID from Hyver (Settings > Company profile > SSO) into the Identifier (Entity ID) field:

  3. Copy the Hyver single sign-on URL into the Reply URL (Assertion Consumer Service URL) field:

  4. Click Save.


4. Configure attributes and claims

  1. In the Attributes & Claims section, click Edit:

  2. Update the values so the email claim is either user.primaryauthoritativeemail or user.mail.

  3. Click Save.


5. Adjust certificate settings

  1. In the SAML Certificates section, click Edit.

  2. Under Signing Option, select Sign SAML response and assertion.

  3. Click Save.


6. Copy values from Azure to Hyver

Go back to Hyver's SSO settings (Settings > Company profile > SSO) and enter the following:

  • App Federation Metadata URL → paste into IdP metadata URL in Hyver.

  • Microsoft Entra Identifier → paste into IdP entity ID in Hyver.

Click Save in Hyver to complete the configuration.


Important notes

  • You must have SSO enabled in Hyver to access the entity ID and SSO URL fields.

  • The edit and save actions in Azure must be completed before copying the metadata into Hyver.

  • Make sure your domain is allowlisted in Hyver before activating Microsoft SSO.


Wrap-up / Next Steps

Once this setup is complete, your users can sign in to Hyver using Entra ID — without needing separate credentials. If you haven’t already enabled SSO in Hyver, see the related guide below.

Did this answer your question?