This page explains how to use Entra ID (Azure Active Directory) as a SAML Identity Provider (IdP)
and configure integration with TrustLogin.
Configuration is performed on both the Entra ID side and the TrustLogin Admin Page.
Prerequisites
- You must apply for the External IdP Integration option of TrustLogin.
- You must create an account in TrustLogin using the same email address as in Entra ID (Azure Active Directory).
Note: If you use the login ID for matching, the email addresses do not need to match.
Reference: NameID Settings for External IdP (SAML) Integration - TrustLogin's External IdP Integration supports only SP Initiated SSO.
- If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
Note: We recommend that administrator users keep password authentication assigned in case of emergency.
Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords
Setup Procedure
Configuration on the Entra ID (Azure Active Directory) Side
Note: For the latest setup instructions, please refer to the manual provided by Microsoft.
Reference (external site): Understand SAML-based single sign-on
-
Open the Azure Portal.
- In "Entra ID (Azure Active Directory)" > "Enterprise applications", select "+ New application".
- Select "Non-gallery application", enter "TrustLogin" as the name, and click the "Add" button.
- In "Properties", set the logo. Also, change "Visible to users?" to "No" and click "Save".
- In "Users and groups", select "+ Add user". Assign the users who will use the IdP integration.
-
In "Single sign-on", select "SAML-based sign-on" for the "Single sign-on mode",
configure each item as follows, and click the "Save" button.Item Setting Value / Details Sign on URL (Optional) Note: External IdP integration usually supports only SP Initiated SSO,
however, setting the following URL in the "Sign on URL" field allows you to initiate login from the IdP.
Configure this as needed.https://portal.trustlogin.com/
Identifier (Entity ID) trustlogin-saml-sp Reply URL (ACS URL) https://portal.trustlogin.com/saml/acs
- At the bottom of the Single sign-on page, download the "Certificate (Base64)" from "SAML Signing Certificate". Also,
note down the "Login URL" and "Azure AD Identifier" found in "Set up TrustLogin".
This completes the configuration on the Entra ID side.
Next, configure the TrustLogin side.
Configuration on the TrustLogin Side
- Log in to TrustLogin,
and open "Settings > Optional Features > External IdP Integration > Settings" on the "Admin Page".
- Open "Add SAML IDP".
-
On the "Create SAML Identity Provider" screen, enter the following information.
Item Setting Value / Details Name Enter any name you like.
Example: Entra ID (Azure Active Directory)SSO URL Configuration on the Entra ID (Azure Active Directory) Side > The "Login URL" value noted in Step 7 Entity ID Configuration on the Entra ID (Azure Active Directory) Side > The "Azure AD Identifier" value noted in Step 7 SAML Identity Provider Certificate Configuration on the Entra ID (Azure Active Directory) Side > The certificate information downloaded in Step 7
Note: Open the certificate in a text editor and copy and paste the text.NameID Format Specify "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress".
Note: For details, seeherePreferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.
Note: For details, seehereCase Sensitive Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
Note: For details, seehere
- Click "Register".
- Next, assign the members who will log in using their Entra ID.
From the External IdP list, click the name of the SAML IDP you just added.
- Click "Add Member". (To add by group, click "Add Group".)
-
Select the target members and click the "Register" button.
The member addition is complete.
This completes the configuration.
Verifying the Configuration
From the TrustLogin login page, enter your company ID and email address, and an Azure Active Directory button will appear. Click it to log in. (Only administrators can also log in using their TrustLogin password.)