Overview
This guide walks you through the steps to configure Microsoft Entra ID (formerly Azure AD) for SAML-based single sign-on with the Cye platform. Once set up, your users can log in using Microsoft credentials, without needing separate Cye platform accounts or passwords.
1. Start in the Azure portal
2. Create and configure the application
In the left-hand menu, under Manage, select Enterprise applications.
Click Create your own application.
Choose Integrate any other application you don't find in the gallery.
Name your application and click Create:
Once created, go to Single sign-on and select the SAML tile.
3. Fill in basic SAML configuration
In the Basic SAML Configuration section, click Edit.
Copy the Cye platform entity ID from the Cye platform (Settings > Company profile > SSO) into the Identifier (Entity ID) field:
Copy the Cye platform single sign-on URL into the Reply URL (Assertion Consumer Service URL) field:
Click Save.
4. Configure attributes and claims
In the Attributes & Claims section, click Edit:
Update the values so the email claim is either
user.primaryauthoritativeemailoruser.mail.Click Save.
5. Adjust certificate settings
In the SAML Certificates section, click Edit.
Under Signing Option, select Sign SAML response and assertion.
Click Save.
6. Copy values from Azure to the Cye platform
Go back to the Cye platform's SSO settings (Settings > Company profile > SSO) and enter the following:
App Federation Metadata URL → paste into IdP metadata URL in the Cye platform.
Microsoft Entra Identifier → paste into IdP entity ID in the Cye platform.
Click Save in the Cye platform to complete the configuration.
Important notes
You must have SSO enabled in the Cye platform to access the entity ID and SSO URL fields.
The edit and save actions in Azure must be completed before copying the metadata into the Cye platform.
Make sure your domain is allowlisted in the Cye platform before activating Microsoft SSO.
Wrap-up / Next Steps
Once this setup is complete, your users can sign in to the Cye platform using Entra ID — without needing separate credentials. If you haven't already enabled SSO in the Cye platform, see the related guide below.








