---
title: MS Azure AD SAML
slug: ms-azure-ad-saml
description: Configure SAML single sign-on with Microsoft Azure AD to authenticate organization users.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-03T13:28:13.882Z
---

:::hint{type="info"}
This feature is available to Enterprise customers.
:::

The following manual configuration creates an SAML SSO configuration for your Enterprise organization.

## Prerequisites

- `Owner` role in an Enterprise organization
- Administrative access to your organization's Microsoft Azure AD portal

## Supported features

This configuration supports the following:

- Service provider initiated SSO
- Single Log Out \[optional]

## Configuration steps

Before configuring SSO, you need to assign a namespace and download your service provider certificate in Make. These steps provide information you need to enter later.

### Create your namespace in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **Namespace**, enter the namespace you want for your organization. For example, `acmecorp`. Your organization members enter this namespace when they log in via SSO.
:::

:::WorkflowBlockItem
Under **SSO type**, select **SAML 2.0**.
:::

:::WorkflowBlockItem
Copy the **Redirect URL** and save it in a safe place. You will use this later when you create your SAML integration in the Microsoft Azure AD portal.
:::
::::

### Create an SAML application in the MS Azure portal

::::WorkflowBlock
:::WorkflowBlockItem
Log in to the [Microsoft Azure portal](https://azure.microsoft.com/en-in/) and navigate to the Azure Active Directory.

![MS Azure portal](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-tD6CsOpNFHk6XV8ajr8R5-20250212-104942.png)
:::

:::WorkflowBlockItem
In the left navigation, click **Enterprise applications.**

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-plGd2Ny-t1DL-eWQw36Ui-20250212-105215.png" size="40" width="317" height="599" position="flex-start" alt="MS Azure Enterprise applications" showCaption="false"}
:::

:::WorkflowBlockItem
Click **+ New Application**.
:::

:::WorkflowBlockItem
Click **+ Create your own application**.
:::

:::WorkflowBlockItem
Enter a name for your app and select **Integrate any other application you don't find in the gallery**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-z-mCMqhk94EWS1ILQMWDt-20250212-112508.png" size="90" width="999" height="520" position="flex-start" alt="Create your own application" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Create**.
:::

:::WorkflowBlockItem
In the left navigation, click **Single Sign-on.**

![Single sign-on](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-E67JElULE2PkIdKkr6OH5-20250212-112942.png)
:::

:::WorkflowBlockItem
Click **SAML**.
:::

:::WorkflowBlockItem
Configure your Basic SAML settings using the Redirect URL (`https://www.make.com/sso/saml/{namespace}`) that you copied in the [the steps above](docId\:leFN8YTGnMlOiWhCpaEUM).&#x20;

| **Field**  | **Value**                                                |
| ---------- | -------------------------------------------------------- |
| Entity ID  | `https://www.make.com/sso/saml/{namespace}/metadata.xml` |
| Reply URL  | `https://www.make.com/sso/saml/{namespace}`              |
| Logout URL | `https://www.make.com/sso/saml/{namespace}`              |

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-g_AKMUUHfRcYX4h00TJ_q-20250212-113753.png" size="80" width="582" height="141" position="flex-start" alt="Basic SAML configuration" showCaption="false"}
:::

:::WorkflowBlockItem
In the **Attributes & Claims** section, click **Edit** to rename your attributes.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-4rtj_xdWWkHSkmGVus4zP-20250212-114014.png" size="80" width="584" height="126" position="flex-start" alt="Attributes and claims" showCaption="false"}
:::

:::WorkflowBlockItem
Under **Additional claims**, find the value you want to edit and click that row.
:::

:::WorkflowBlockItem
Enter the new name in the Name field. Use the following chart to find the names required for your IML resolve.

| **Field**              | **Value**              |
| ---------------------- | ---------------------- |
| email                  | user.mail              |
| name                   | user.displayname       |
| id                     | user.userprincipalname |
| Unique User Identifier | user.userprincipalname |
:::

:::WorkflowBlockItem
Click **Save**.
:::

:::WorkflowBlockItem
Copy the **Login URL** and save it in a safe place.&#x20;

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-ASoASMJC8M9JVykO29Ihk-20250212-114639.png" size="80" width="1280" height="344" position="flex-start" alt="Login and logout URL" showCaption="false"}
:::
::::

### Download the SAML certificate

You need to download the base 64 SAML certificate from Microsoft Azure and upload it to the **Identity Provider Certificate** field of the **SSO** tab in your Make organization.

::::WorkflowBlock
:::WorkflowBlockItem
Find the **SAML Certificates** section of your single sign-on settings in the Microsoft Azure portal.
:::

:::WorkflowBlockItem
Next to **Certificate (Base64)**, click **Download**.
:::
::::

Your browser automatically downloads the `.cer` file.&#x20;

### Update the SSO in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **Identity Provider Certificate**, click **Extract**. A pop-up appears.
:::

:::WorkflowBlockItem
Under **P12, PFX or PEM file**, click **Choose file** and select the `.cer` file you downloaded.
:::

:::WorkflowBlockItem
Enter the following information from MS Azure into the **IdP login URL** and **Identify provider certificate** fields.

| **Field**                     | **Value to enter from MS Azure** |
| ----------------------------- | -------------------------------- |
| IdP login URL                 | Login URL                        |
| Identity provider certificate | Certificate (Base 64)            |
:::

:::WorkflowBlockItem
Enter the following in the **Login IML resolve** field:

```javascript
{    
    "email":"{{get(user.attributes.email, 1)}}",
    "name":"{{get(user.attributes.firstName, 1)}} {{get(user.attributes.lastName, 1)}}",
    "id":"{{user.name_id}}"
} 
```
:::

:::WorkflowBlockItem
Select the following settings:

| **Field**                    | **Value** |
| ---------------------------- | --------- |
| Allow Unencrypted Assertions | Yes       |
| Allow Unsigned Responses     | No        |
| Sign Requests                | Yes       |

![SSO Settings](https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-3yxio08te9esClNkt-wjX-20250212-120230.png)
:::

:::WorkflowBlockItem
Click **Save**.
:::
::::

:::hint{type="info"}
You will receive an email with the subject "Activation complete: SSO ready for your organization" upon successful activation. If you encounter any issues while logging in using SSO, disable SSO using the "one-time link" (valid for 24 hours).&#x20;
:::



## Service Provider initiated SSO

::::WorkflowBlock
:::WorkflowBlockItem
Go to [make.com](https://make.com).&#x20;
:::

:::WorkflowBlockItem
Click **Sign in with SSO**.
:::

:::WorkflowBlockItem
Enter the namespace you chose for your organization.
:::

:::WorkflowBlockItem
Log in using your Microsoft credentials and consent to Make's access to your user data.
:::
::::

