Microsoft Entra ID SAML SSO setup
Use this page when your IT team is creating a Microsoft Entra ID enterprise application for Artifactive. Your Artifactive dashboard shows the setup values for your tenant, and we can help if your team wants an assisted setup.
How setup works
- Artifactive provides service-provider values in the dashboard.
- Your Microsoft Entra ID admin creates a non-gallery enterprise application.
- Your Microsoft Entra ID admin configures SAML single sign-on.
- Your Microsoft Entra ID admin enters the Artifactive Entity ID as the Identifier and the Artifactive ACS URL as the Reply URL.
- Your Microsoft Entra ID admin assigns the users or groups that should have access.
- Artifactive records the Microsoft Entra identity-provider metadata.
- An Owner runs Test SSO in Artifactive before enabling SSO-only access.
Values from Artifactive
| Value | How it is used |
|---|---|
| Identifier (Entity ID) | Paste the Artifactive Entity ID into Microsoft Entra ID as the Identifier. |
| Reply URL (Assertion Consumer Service URL) | Paste the Artifactive ACS URL into Microsoft Entra ID as the Reply URL. |
| Sign on URL | Leave blank unless Artifactive provides one. |
| Relay State | Leave blank unless Artifactive provides one. |
Values from your identity provider
- Federation Metadata XML URL or metadata XML, preferred.
- Microsoft Entra Identifier / Issuer.
- Login URL / SSO URL.
- SAML signing certificate.
- Assigned users or groups.
Microsoft Entra ID notes
- Create a non-gallery enterprise application.
- Choose SAML as the single sign-on method.
- Use the Artifactive Entity ID for Identifier.
- Use the Artifactive ACS URL for Reply URL.
- Assign the users or groups that should open Artifactive dashboards.
Testing before enforcement
- Run Test SSO from Artifactive.
- Test with an assigned user on an approved company email domain.
- Do not switch to SSO-only until the test passes.
- For team SSO-only, confirm Owner access and recovery before enforcing it.
Common setup issues
- User is not assigned to the SAML app.
- ACS URL or Entity ID does not exactly match.
- NameID/email is missing or not the user's work email.
- Metadata or signing certificate changed after setup.