About this page
This page explains how to use Microsoft Entra ID (formerly Azure AD) as an IdP and set up SAML integration with ZUNDA ID. Once you complete this setup, users signed in to Microsoft Entra ID can use those credentials to log in to ZUNDA ID via single sign-on.
What you'll need
Make sure you have the following ready in advance.
-
A Microsoft Entra ID user with permission to manage enterprise applications
You need one of the following roles: Enterprise Application Administrator, Application Administrator, Cloud Application Administrator, or Global Administrator.
-
A ZUNDA ID user with authentication method admin permissions
You need a user with ZUNDA ID admin permissions to create and configure the SAML provider.
-
A recovery key issued and stored in advance
To prevent a lockout caused by a misconfiguration or an IdP outage, see How to Configure Recovery Settings for Login Methods and issue a recovery key in advance.
Setup steps
You'll switch back and forth between ZUNDA ID and the Microsoft Entra admin center. It's easiest to keep both open at the same time.
- Open the Login Method Settings screen in ZUNDA ID, and click Add SAML Provider.
Enter a display name of your choice to identify this provider (for example, Microsoft Entra ID), and click Create to go to the provider details screen. The name you enter here is shown on the login screen and in settings screens.
- Log in to the Microsoft Entra admin center (entra.microsoft.com), and from Enterprise applications, open the screen for creating a New application.
- Click Create your own application and configure the following on the screen that appears.
Because ZUNDA ID isn't listed in the Microsoft Entra app gallery, you need to select Integrate any other application you don't find in the gallery (Non-gallery).
- What's the name of your app?
ZUNDA ID
- What are you looking to do with your application?
Integrate any other application you don't find in the gallery (Non-gallery)
Confirm your selections and click Create.
- Once the application is created, a details screen appears. Select Single sign-on from the left menu, and click SAML on the Select a single sign-on method screen.
- Return to the provider details screen in ZUNDA ID, click Download next to Metadata XML (SP), and save the SP metadata XML.
The SP metadata contains the ZUNDA ID (SP) information Microsoft Entra ID needs, such as the ACS URL and entity ID. Uploading this file to Microsoft Entra ID lets you populate the SP settings in one step.
- Return to the SAML single sign-on setup screen in the Microsoft Entra admin center, click Upload metadata file, and upload the SP metadata XML file you downloaded earlier.
- Confirm that the values were filled in automatically, and click Save.
The Identifier and Reply URL fields are filled in automatically from the metadata file. These correspond to ZUNDA ID's entity ID and ACS URL respectively.
Once you've confirmed the save, click the ❌ button to close the Basic SAML Configuration panel.
- Scroll down the Set up single sign-on with SAML screen in the Microsoft Entra admin center, find the SAML Certificates section, and click the download link next to Federation Metadata XML to save the XML file.
This federation metadata includes the Microsoft Entra ID IdP certificate and SSO URL — importing it into ZUNDA ID lets you bring in all of these IdP-side settings at once.
- Return to the provider details screen in ZUNDA ID, and click Import Metadata XML.
In the dialog that appears, click Upload from file and select the federation metadata XML file you downloaded earlier. Once you confirm it has loaded, click Import Metadata XML.
Confirm that the IdP Entity ID, SSO URL, IdP certificate, and other values have all been imported. This completes the SAML provider setup on the ZUNDA ID side for now, but you'll adjust the attribute mapping on the Microsoft Entra ID side in the next step.
- Return to the Microsoft Entra admin center, and click Edit in the Attributes & Claims section.
By default, Microsoft Entra ID maps the user's principal name (in email address format) to the name claim. Because ZUNDA ID displays this value as the "display name," you'll remap it to the more appropriate displayName attribute.
ZUNDA ID uses displayName for the display name, but Microsoft Entra ID's default configuration maps user.userprincipalname to the name claim. To correctly import the user's display name, click the claim for http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name to open the edit screen.
On the edit screen, change the Source attribute from user.userprincipalname to user.displayname, and click Save.
Back on the list, confirm that the value of the name claim has changed to user.displayname, then click the ❌ button to close the screen. This completes all the necessary configuration on the Microsoft Entra ID side.
Registering the SP certificate
This step isn't required, but registering the ZUNDA ID SP certificate with Microsoft Entra ID and enabling SAML request signature verification lets Microsoft Entra ID cryptographically verify that a request genuinely came from ZUNDA ID, strengthening protection against impersonation.
- From the SP Certificates section of the Microsoft Entra ID provider details screen in ZUNDA ID, click Download next to the primary certificate to save the SP certificate file (.cer).
- Return to the SAML single sign-on setup screen in the Microsoft Entra admin center, and scroll down to the SAML Certificates section.
- Click Edit next to Verification certificates (Optional).
- When the Verification certificates panel opens, click the folder icon and select the SP certificate file (.cer) you downloaded earlier, then click OK.
- Confirm that the certificate's thumbprint and key ID are listed, check Require verification certificates, and click Save to complete the certificate registration.
Microsoft Entra ID now verifies the signature of SAML requests sent from ZUNDA ID. If you ever replace the SP certificate, update the verification certificate on the Microsoft Entra ID side using the same steps.
Login test
Once the setup is complete, always run a login test before enabling the provider to confirm the settings are correct and that Microsoft Entra ID user information imports correctly.
- From the Microsoft Entra ID provider details screen in ZUNDA ID, click the Test button.
Clicking the Test button opens the Microsoft login screen in a pop-up window. If pop-ups are blocked, temporarily disable your browser's pop-up blocker.
- Once you complete authentication with Microsoft, "SSO login test succeeded" is displayed as shown below, and the setup is complete once the check results for NameID, Email, Surname, Given name, and Display name all show green checkmarks.
If an error is displayed, or a check item is marked in red, check the following:
- Whether the federation metadata XML was imported correctly
- Whether the source attribute of the
nameclaim was changed touser.displayname - Whether the test user has a last name, first name, and display name configured on the Microsoft Entra ID side
Once the test succeeds, return to the provider details screen and switch Status to ON to enable SAML login via Microsoft Entra ID. After that, select this provider as a login method in Domain Settings so actual users can log in using SAML authentication.
We strongly recommend completing How to Configure Recovery Settings for Login Methods in advance, in case the login method becomes unavailable. Once your setup is complete, see How to Use the SAML Provider You Created as a Login Method to enable it as a login method.