Entra ID
Last updated
Last updated
This page provides step-by-step instructions for setting up Entra ID as your identity provider for Single Sign-On (SSO) in BirdCRM using SAML.
Configuration overview:
Step 1: Start Entra ID – Begin by setting up specific configurations within your Entra ID account.
Step 2: BirdCRM Steps – Follow the required steps within BirdCRM to integrate with Entra ID.
Step 3: Finalize Entra ID – Complete the configuration by finalizing settings in Entra ID.
Navigate to Enterprise Applications in Entra ID and click on New application.
Click on Create your own application.
Give the application a name such as BirdCRM and select Integrate any other application you don’t find in the gallery (Non-gallery) and click Create.
Click on '2 Setup single sign on'
Click on SAML.
Scroll down to section 3 'SAML Certificates' and click copy on the App Federation Metadata Url. You will need this URL to setup SAML in BirdCRM in the next section.
Navigate to the Access Settings in BirdCRM located here and click on Set up SSO and select SAML.
Enter a name for your SSO connection in BirdCRM and paste the metadata URL in the File URL text box and click Confirm.
Your SAML integration is now saved.
The next steps are to add one or more domains that you can login with and also retrieve the required values to complete the Entra ID settings. The order is not important but these instructions will perform the domain validation first and then retrieve the values to use in Entra ID.
To start with, select your SSO integration and click on View.
Now we will validate your domain(s) that you will login from Entra ID with. First click on the Domain Validation button available when viewing your SSO integration
Enter your company domain name that you login with (e.g. companyname.com) and click Create.
You will then be presented with a unique string under the Challenge column that needs to be placed as a TXT record in your domain. If you are unsure how to add a TXT record please consult with your DNS provider.
Once you have added the TXT record to verify your domain, you can select Verify.
If the TXT record was added correctly it will then show the Status of Verified.
Now we can get the final details to complete the Entra ID configuration. Click on Details in the SSO configuration.
From this screen you will need to take a copy of the Single Sign On URL and the Audience URI fields which will be used to complete your Entra ID configuration.
From the Single Sign-On section of your BirdCRM application in Entra ID, click on the Edit button under the Basic SAML Configuration box.
Fill out the Audience URI you copied from BirdCRM in the Identifier (Entity ID) field and the Single Sign On URL you copied from BirdCRM in the Reply URL field. You can leave the other fields blank. Click on Save.
Click on the Edit button under Attributes & Claims.
Click on Add new claim and enter email as the Name and user.userprincipalname as the Source attribute and click Save.
Repeat and add another claim with the Name name and the Source attribute user.givenname.
Remove any other Additional claims by clicking on the three dots menu for each claim and clicking Delete. Once you have removed the extra default claims, your Attributes & Claims section should look like this. Please note that name can be set to another value if necessary but it must have a value associated with it for each user.
You have now completed the Entra ID SSO setup. Make sure that you assign the application to your users and groups as required.