Microsoft Entra ID SAML integration

To begin with the integration process, Login to the Microsoft Entra ID Portal.

Step 1: Create an Enterprise Application

To create the Enpass application in your Entra ID portal, follow these steps:

  1. In the Microsoft Entra ID portal, select Enterprise Applications from the sidebar.

  2. Click New Application > Create your own application.

  3. Enter a name for your application (e.g., "Enpass SSO").

  4. Select Integrate any other application you don’t find in the gallery (Non-gallery).

  5. Click Create.

Once the application is created:

  1. In the sidebar, select Single sign-on.

  2. Choose SAML as the single sign-on method.

Step 2: Set up Single Sign-On with SAML

Configure SAML Configuration

  1. Under Basic SAML Configuration, click Edit.

  2. Add the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) as provided by Enpass Admin Console.

  3. Click Save.

  4. Click on the Close icon on the right top corner.

    configure SAML config

Configure Attributes & Claims

  1. Under Attributes & Claims, click Edit.

  2. In the Additional Claims section, locate and click on the claim with value user.email.

  3. In the Manage claim window:

    • Update the Name field to “email”.

    • Clear the Namespace field.

    • Click Save.

  4. Click on the Close icon on the right top corner.

    You can safely delete the extra claims other than 'email'.

    config claims atrrs

Configure SAML Certificates

  1. Click on Edit next to Token signing certificate and update the Signing Option to "Sign SAML response and assertion".

  2. Click Save.

  3. Click on the Close icon on the right top corner.

  4. In the SAML Certificates section, copy the App Federation Metadata URL.

  5. Use this URL to complete the SSO Connector setup in the Enpass  Admin Console.

Step 3: Assign Users to the Application

All administrators of the Enpass Admin Console should be assigned to this application to enable SSO login.

  1. In the sidebar, under the Manage section, select Users & Groups.

  2. Assign Enpass admin console users to the application.