Skip to main content

Configure Microsoft Entra ID for SSO

How to integrate Microsoft Entra ID with the Cye platform for SAML-based single sign-on.

Overview

This guide walks you through the steps to configure Microsoft Entra ID (formerly Azure AD) for SAML-based single sign-on with the Cye platform. Once set up, your users can log in using Microsoft credentials, without needing separate Cye platform accounts or passwords.


1. Start in the Azure portal

  1. Open the Azure portal:

  2. Click View under the Manage Microsoft Entra ID tile.


2. Create and configure the application

  1. In the left-hand menu, under Manage, select Enterprise applications.

  2. Click Create your own application.

  3. Choose Integrate any other application you don't find in the gallery.

  4. Name your application and click Create:

  5. Once created, go to Single sign-on and select the SAML tile.


3. Fill in basic SAML configuration

  1. In the Basic SAML Configuration section, click Edit.

  2. Copy the Cye platform entity ID from the Cye platform (Settings > Company profile > SSO) into the Identifier (Entity ID) field:

  3. Copy the Cye platform single sign-on URL into the Reply URL (Assertion Consumer Service URL) field:

  4. Click Save.


4. Configure attributes and claims

  1. In the Attributes & Claims section, click Edit:

  2. Update the values so the email claim is either user.primaryauthoritativeemail or user.mail.

  3. Click Save.


5. Adjust certificate settings

  1. In the SAML Certificates section, click Edit.

  2. Under Signing Option, select Sign SAML response and assertion.

  3. Click Save.


6. Copy values from Azure to the Cye platform

Go back to the Cye platform's SSO settings (Settings > Company profile > SSO) and enter the following:

  • App Federation Metadata URL → paste into IdP metadata URL in the Cye platform.

  • Microsoft Entra Identifier → paste into IdP entity ID in the Cye platform.

Click Save in the Cye platform to complete the configuration.


Important notes

  • You must have SSO enabled in the Cye platform to access the entity ID and SSO URL fields.

  • The edit and save actions in Azure must be completed before copying the metadata into the Cye platform.

  • Make sure your domain is allowlisted in the Cye platform before activating Microsoft SSO.


Wrap-up / Next Steps

Once this setup is complete, your users can sign in to the Cye platform using Entra ID — without needing separate credentials. If you haven't already enabled SSO in the Cye platform, see the related guide below.

Did this answer your question?