Microsoft Entra ID SSO
Configure SAML SSO between Microsoft Entra ID and platform, including domain verification, attribute claims, relay status, and common troubleshooting.
This guide guides you through setting a single SAML record between Microsoft Entra ID (formerly Azure Active Directory) and the platform.
Prerequisites
Section entitled ‘Prerequisites’- Microsoft Entra ID administrator access (or application administrator role)
- the platform organization administrator access
- Your platform domain (for example,
probo.example.com) - Access to DNS settings for domain verification
Prepare the platform Information
Section entitled “Prepare the Platform Information”Before you set up your Microsoft Entra ID, collect the following details about the platform service provider:
| Field | Value |
|---|---|
| ACS URL | https://your-probo-domain.com/api/connect/v1/saml/2.0/consume |
| Entity ID | https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata |
Replace your-probo-domain.com with your actual platform domain.
Domain Verification
Section “Domain Verification”Before you set up anything else, you need to check the domain property:
- Log in to the platform as an organization administrator
- Go to Organization Settings → Authentication → SAML
- Click Verify Domain (If there are no configurations yet, this option will be available)
- Copy the provided TXT record value
- Add a TXT record to your domain’s DNS settings:
Type: TXTName: _probo-domain-verification.your-company.comValue: [Verification token from Probo]TTL: 300 (or your DNS provider's default)
- Wait for DNS propagation (usually 5-15 minutes)
- In the platform, click Complete Verification
- In case of success, the domain status will be displayed as "Verified"
Configure Microsoft Entra ID
Section entitled “Configure Microsoft Entra ID”-
Signed to Microsoft Entra admin center
-
Go to Identity → Applications → Enterprise applications
-
Click New application → Create your own application
-
Enter
Proboas the application name -
Select Incorporate any other application that you do not find in the gallery (non-gallery)
-
Click Create
-
In the application view, go to Single sign-on → select SAML
-
In Basic SAML Configuration, click Edit and configure:
Field Value Identifier (Entity ID) https://your-probo-domain.com/api/connect/v1/saml/2.0/metadataReply URL (Assertion Consumer Service URL) https://your-probo-domain.com/api/connect/v1/saml/2.0/consumeRelay State [SAML Configuration ID](optional - see note below)Sign on URL https://your-probo-domain.com(optional)Important: The Relay State is optional, but if you want to support the connection streams initiated by IdP, it must be set to your exact SAML configuration ID (not a locholder). If the setting is incorrect, SSO will not work. You will get this ID after creating the SAML configuration in the platform. You can initially leave this ID empty and you can update it later with the exact configuration ID.
-
Click Save
-
In Attributes & Claims, click Edit Configure the following claims:
Claim name Source attribute emailuser.mailfirstNameuser.givennamelastNameuser.surnameTo add each claim:
- Click Add new claim
- Enter the name of the complaint (for example,
email) - Set Source to
Attribute - Select the corresponding Source attribute
- Click Save
Also check that Unique User Identifier (Name ID) is set to
user.userprincipalnameoruser.mailwith the formatEmail address. -
In SAML CertificatesDownload the Certificate (Base64) and copy:
- Login URL (This is the URL of IDP SSO)
- Microsoft Entra Identifier (This is the ID of the IDP entity)
-
Go to Users and groups
-
Click Add user/group
-
Select users or groups that should have access to the platform
-
Click Assign
Configure the platform
Section entitled “Configure the platform”-
Log in to the platform as an organization administrator
-
Go to Organization Settings → Authentication → SAML
-
Click Add SAML Configuration
-
Configure the basic settings:
Field Value Notes Email Domain your-company.comYour organization’s email domain Enforcement Policy OPTIONALRecommended for initial setup -
Configure identity provider settings with values in Microsoft Entra ID:
Field Value Notes IdP Entity ID [Microsoft Entra Identifier]Copy from Entra ID setup IdP SSO URL [Login URL]Copy from Entra ID setup IdP Certificate [Certificate (Base64)]Paste the downloaded certificate content -
Configure the attribute mappings:
Field Value Notes Email Attribute emailMaps to user email First Name Attribute firstNameMaps to user first name Last Name Attribute lastNameMaps to user last name Role Attribute [Leave empty]Optional; map to send ___ZBT_I18N_RUNTIME_BLOCK_202__, ___ZBT_I18N_RUNTIME_BLOCK_203__, ___ZBT_I18N_RUNTIME_BLOCK_204__, or VIEWER -
Configure user settings:
Field Value Notes Auto Signup EnabledAllows new users to automatically register through SSO -
Click Save Configuration
-
Copy the SAML Configuration ID which appears after saving (for example,
saml_config_1a2b3c4d)
Update Entra ID Relay State
Section titled “Update Entra ID Relay State”Return to Microsoft Entra ID to enable ID initiated authentication:
- Go to your platform application in the Entra administration center
- Click Single sign-on → Edit Basic SAML Configuration
- In the Relay State field, enter your SAML configuration ID
- Click Save
Troubleshooting
Section “Troubleshooting”"AADSTS75005: The application is not a valid Saml2 protocol message" Error
“AADSTS75005: The request is not a valid Saml2 protocol message” Error- Cause: Incorrect Reply URL or Entity ID configuration
- SolutionCheck if the Reply URL and Entity ID in Entra ID match exactly your platform configuration:
- Reply URL:
https://your-probo-domain.com/api/connect/v1/saml/2.0/consume - Entity ID:
https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
- Reply URL:
“AADSTS50105: User not assigned to application” Error
Section entitled “AADSTS50105: User not assigned to application” Error- CauseThe user has not been assigned to the Enterprise application of the platform
- SolutionGo to the Enterprise App Users and groups Assign to a user or group that contains the user
“AADSTS700016: Application not found” Error
AADSTS700016: Application not found Error- CauseThe incorrect entity ID in the platform or application is not configured correctly
- SolutionCheck if the Microsoft Entra Identifier matches the entity ID set up on the platform
Attributes Not Mapping
Section titled “Attributes Not Mapping”- Cause: Claims not configured correctly in Entra ID
- SolutionCheck if the custom requests are configured with the exact names:
email,firstName,lastName. Check below Single sign-on → Attributes & Claims
“Invalid RelayState” Error
Section titled “Invalid RelayState” Error”- Cause: Incorrect Relay State configuration
- SolutionMake sure the relay status is either empty or set to the exact SAML configuration ID on the platform
Debugging Steps
Posts Tagged ‘Debugging Steps’Check Entra ID Sign-in Logs
Section entitled “Check Entra ID Sign-in Logs”- Go to the Enter Administration Center Identity → Monitoring & health → Sign-in logs
- Filter by application platform
- Click a failed connection attempt to view error details and troubleshooting recommendations
Test SAML Response
Section entitled “SAML Response Test”- In the Enterprise Platform application, access Single sign-on
- Click Test this application
- Check the SAML response for errors
Advanced Configuration
Section “Advanced Configuration”Custom Claims
Section titled “Custom Claims”To map additional Entra ID user attributes:
- In the Enterprise app, go to Single sign-on → Attributes & Claims
- Click Add new claim
- Map additional directory attributes as needed
- Updating corresponding attribute maps in the platform
Conditional Access
Section “Conditional Access”Control access using Microsoft Entra ID Conditional Access policies:
- Go to Identity → Protection → Conditional Access
- Creating a new policy targeting the application of the Platform
- Configure conditions (location, device, risk level, etc.)
- Set up appropriate access controls (grant, block, requires MFA)
Group-Based Access
Section “Group-Based Access”Restrict access using Entra ID groups:
- In the Enterprise app, go to Users and groups
- Assign groups instead of individual users
- Manage access by adding/removing users from assigned groups
For detailed troubleshooting and advanced configuration options, see SSO Overview guide.