Skip to content

Entra ID SSO

Create a Microsoft Entra ID enterprise app with SAML, then paste its App Federation Metadata URL into Avaloi.

Connect Microsoft Entra ID to Avaloi with SAML 2.0. Only the Owner can save the connection, and it is for Enterprise accounts. The full flow, including domain proof, testing, and mandatory sign-on, is in Single sign-on with SAML.

Connect Microsoft Entra ID

  1. Create an enterprise app. In Entra ID, add a non-gallery enterprise application and choose SAML for single sign-on. Assign the users or groups who should reach Avaloi.
  2. Add the Avaloi details. Set Identifier (Entity ID) to the Entity ID and Reply URL (Assertion Consumer Service URL) to the ACS URL, both from the Single sign-on page in Avaloi.
  3. Set the claims. Send the user's email as the Unique User Identifier (Name ID) with the format Email address, or send user.mail as the claim email. To give roles by group, add a group claim named groups.
  4. Sign the assertion. In SAML Certificates, set Signing Option to Sign SAML assertion. Use SHA-256.
  5. Copy the App Federation Metadata Url.
  6. In Avaloi, open Company settings, then Single sign-on, then Enable. Paste the metadata URL, list your email domains, and save.
  7. Add the DNS TXT record Avaloi shows under Domain proof, choose Verify domain, then choose Test connection.
  8. Sign in once through Sign in with your company. When that works, turn on Mandatory single sign-on if you want it.

Quick answers

Can I use OpenID Connect? Not yet. Avaloi supports SAML 2.0.

Avaloi refused the response. Check that the assertion is signed, that the email is the NameID or the email attribute, and that the email is on a domain you verified. See the fixes in Single sign-on with SAML.

Members are stuck in a loop. The Owner can always sign in with a password. Turn Mandatory single sign-on off, fix the connection, run Test connection, then turn it on again.

API

  • GET /v1/companies/me/sso/sp-metadata
  • PUT /v1/companies/me/sso
  • POST /v1/companies/me/sso/test

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.