--- title: "SAML With Microsoft Entra ID" slug: "example-saml-with-microsoft-entra-id" updated: 2025-06-26T21:29:03Z published: 2025-06-26T21:29:03Z canonical: "docs.processmaker.com/example-saml-with-microsoft-entra-id" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # SAML With Microsoft Entra ID > [!TIP] > [**Plan Availability:**](https://www.processmaker.com/products/pricing/) ![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Standard.png)![Professional](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Professional.png)![Enterprise](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/Enterprise.png) Configure ProcessMaker Platform and PM Classic to use SSO SAML authentication with the identity provider [Microsoft Entra ID](https://learn.microsoft.com/en-us/entra/fundamentals/new-name) (Microsoft Azure Active Directory) as follows: 1. [Create and configure an enterprise application in Microsoft Entra ID](/v1/docs/example-saml-with-microsoft-entra-id#create-and-configure-an-enterprise-application-in-microsoft-entra-id) 2. [Configure ProcessMaker using SAML with Microsoft Entra ID](/v1/docs/example-saml-with-microsoft-entra-id#configure-processmaker-using-saml-with-microsoft-entra-id) 3. [Configuration for PM Classic (needed only for PM Classic users)](/v1/docs/example-saml-with-microsoft-entra-id#configuration-for-pm-classic) 4. [Configure the web browser](/v1/docs/example-saml-with-microsoft-entra-id#web-browser-configuration) > [!NOTE] > - It is recommended to create and configure an enterprise application in Microsoft Entra ID concurrently with configuring ProcessMaker Platform and PM Classic. This is because each configuration procedure requires values from the other. > - The web browser must support third-party cookies. ## Create and Configure an Enterprise Application in Microsoft Entra ID Follow these steps to add an enterprise application in Microsoft Entra ID: 1. [Log on](https://portal.azure.com/) to your Microsoft Azure account. The **Welcome to Azure!** window displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(302).png) 2. Click **View** in the **Manage Microsoft Entra ID** section. The **Default Directory** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(304).png) 3. Click **Enterprise Applications**, then select the **All Applications** option. The **Browse Microsoft Entra Gallery** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(305).png) 4. Click **Create your own application**. Create your own application screen displays on the right. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(306).png) 5. From the **Create your own application screen:** 1. In the **What's the name of your app?**, enter the application name. 2. Select **Integrate any other application you don't find in the gallery (Non-gallery).** 3. Click **Add**. 6. On the sidebar, click **Single sign-on**. The **Single sign-on** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(307).png) 7. Click the **SAML** option. The **SAML-based Sign-on** page displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(308).png) 8. From the **Basic SAML Configuration** section, click the **Edit** link. The **Basic SAML Configuration** page displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(309).png) 9. Pause this procedure, and then begin [configuring the ProcessMaker Platform SAML authentication](/v1/docs/example-saml-with-microsoft-entra-id) until the **SSO - SAML** settings display. ## Configure ProcessMaker Using SAML With Microsoft Entra ID **Permissions** Your user account or group membership must have the "Settings: Update Settings" permission to edit SSO SAML settings unless your user account has the **Make this user a Super Admin** setting selected. See the [Settings](/v1/docs/permission-descriptions-for-users-and-groups#settings) permissions or ask your Administrator for assistance. > [!WARNING] > ### Notice to Administrators > > [Enhance security for your ProcessMaker Platform instance by following these best practices](/v1/docs/enhance-processmaker-platform-security). Among these best practices are to require all ProcessMaker users to log on to your ProcessMaker Platform instance via Single Sign-On (SSO), OAuth, OKTA and/or two-factor authentication. Follow these steps to configure SAML SSO settings with Microsoft Entra ID as necessary: 1. [View your SSO Settings](/v1/docs/sso-settings#view-sso-settings). From the list of SSO identity providers, enable the **SAML** option. The **SSO - SAML** tab displays. 2. Click the **SSO - SAML** tab. The **SSO - SAML** settings display. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/40e75e62-db53-438e-aa7b-aee6c32a6184.png) 3. In Microsft Azure, go to the **Basic SAML Configuration**. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/25a4bd39-ae34-4c9e-a031-dd7ef39942a1.png) 4. Copy the ProcessMaker Platform settings from the **SSO - SAML** settings in step two to Microsoft Azure settings in step three as follows: - Use the copy icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e84ac12c-3e21-4f30-a564-ae87b66ae863.png) to copy the URL from the **ACS Url** setting, and then provide it to the **Add reply URL** setting. - Use the copy icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e84ac12c-3e21-4f30-a564-ae87b66ae863.png) to copy the URL from the **Entity ID (Metadata)** setting, and then provide it to the **Add identifier** setting. - Use the copy icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/e84ac12c-3e21-4f30-a564-ae87b66ae863.png) to copy the URL from the **Single Logout URL** setting, and then provide it to the **Logout Url (Optional)** setting. 5. In Microsoft Azure, go to the **Set up** section and copy the following fields: 1. **Login URL** 2. **Microsoft Entra Identifier** 3. **Logout URL** ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/dfe4a4f1-369b-4782-8961-52f0503171a0.png) 6. In ProcessMaker Platform, go to the following settings: ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/d6c6b399-fa1c-4a91-be35-76d2fbe68047.png) Copy Microsoft Azure settings described in step five as follows: - Click the **Edit** icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/12fe30b8-311c-4be1-878e-be2598f2a401.png)for the **SSO Endpoint** setting. Enter the identity provider URL from which ProcessMaker retrieves the authentication response and validates it when establishing the SSO session. Get this value from the **Login URL** value of Microsoft Azure settings described in step five. - Click the **Edit** icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/12fe30b8-311c-4be1-878e-be2598f2a401.png)for the **SSO Identifier** setting. Enter the URL that references the SAML XML file for your identity provider (IdP). Get this value from the **Microsoft Entra Identifier** value of Microsoft Azure settings described in step five. - Click the **Edit** icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/12fe30b8-311c-4be1-878e-be2598f2a401.png)for the **SLO Endpoint** setting. Enter the logout URL. Get this value from the **Logout URL** value from the **Microsoft Entra Identifier** value of Microsoft Azure settings described in step five. 7. In the **Encryption Type** setting, select the encryption type set in your Microsoft Azure environment. For this example, leave the default value as **RSA_SHA1**. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/5b908d8c-6139-4609-bca6-cc8c6f3205ae.png) 8. In Microsoft Azure, go to the **SAML Certificates** section and download the **Certificate (Base 64)** file. Open the file, copy all the content including **BEGIN/END** certificate lines. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/288e5eb2-1204-47cd-bdba-e2d6d911c088.png) 9. In ProcessMaker Platform, click the **Edit** icon![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/12fe30b8-311c-4be1-878e-be2598f2a401.png)for the **Public Certificate** setting. The **Public Certificate** screen displays. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/fe95c786-b7e5-40f1-a628-728ff44f9f8f.png) 10. If Microsoft Azure requires, enter the identity provider's certificate fingerprint. Get this value from the **SAML Certificates** setting in step eight. 11. Click the **Edit** icon ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(310).png) for the **Variable Map** and the **User Matching** setting. In this case, the **Variable Map** screen displays default values. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(311).png) Variable Map 12. Match the variables of the **User Matching** and **Variables Map** fields with one of the following Microsoft Azure data according to your needs and attributes available: - The attributes retrieved from the **Federation Metadata** XML file. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(312).png) - The data in the **Attributes** and Claims sections. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(313).png) 13. In Microsoft Azure, do the following: - In the **SAML Certificates** section, download the **Federation Metadata XML** file. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(316).png) - Open the file. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(315).png) 14. In ProcessPlatform, click the **Copy** icon for the **Name ID Format** setting to copy this value in the **Required claim** setting when configuring Microsoft Azure. Otherwise, leave with the default value. ![](https://cdn.document360.io/2d311614-fcb7-4424-8b4c-d4d3091eebeb/Images/Documentation/image(314).png) 15. [Configure PM Classic.](/v1/docs/example-saml-with-microsoft-entra-id) ## Web Browser Configuration > [!WARNING] > #### Configure the Web Browser > > To complete the SSO configuration, it is necessary to allow third-party cookies in the web browser. See instructions to enable cookies for your respective browse using the following links: > > - [Manage cookies in Chrome](https://support.google.com/chrome/answer/95647?hl=en&co=GENIE.Platform%3DDesktop) > - [Manage cookies in Firefox](https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer) ## Related - [SSO - SAML Settings](/sso-saml-settings.md) - [SSO Settings](/sso-settings.md)