How to Configure Entra ID (Azure Active Directory) External IdP Integration

This page explains how to use Entra ID (Azure Active Directory) as a SAML Identity Provider (IdP)
and configure integration with TrustLogin.

Configuration is performed on both the Entra ID side and the TrustLogin Admin Page.

Prerequisites

  • You must apply for the External IdP Integration option of TrustLogin.
  • You must create an account in TrustLogin using the same email address as in Entra ID (Azure Active Directory).
    Note: If you use the login ID for matching, the email addresses do not need to match.
     Reference: NameID Settings for External IdP (SAML) Integration
  • TrustLogin's External IdP Integration supports only SP Initiated SSO.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: We recommend that administrator users keep password authentication assigned in case of emergency.
     Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords

Setup Procedure

Configuration on the Entra ID (Azure Active Directory) Side

Note: For the latest setup instructions, please refer to the manual provided by Microsoft.
 Reference (external site): Understand SAML-based single sign-on

  1. Open the Azure Portal.
  2. In "Entra ID (Azure Active Directory)" > "Enterprise applications", select "+ New application".
    AzureAD01.png
  3. Select "Non-gallery application", enter "TrustLogin" as the name, and click the "Add" button.
    AzureAD01.png
  4. In "Properties", set the logo. Also, change "Visible to users?" to "No" and click "Save".
    AzureAD02.png
  5. In "Users and groups", select "+ Add user". Assign the users who will use the IdP integration.
    AzureAD04.png
  6. In "Single sign-on", select "SAML-based sign-on" for the "Single sign-on mode",
    configure each item as follows, and click the "Save" button.

    Item Setting Value / Details
    Sign on URL (Optional)

    Note: External IdP integration usually supports only SP Initiated SSO,
     however, setting the following URL in the "Sign on URL" field allows you to initiate login from the IdP.
     Configure this as needed.

    https://portal.trustlogin.com/

    Identifier (Entity ID) trustlogin-saml-sp
    Reply URL (ACS URL) https://portal.trustlogin.com/saml/acs

    AzureAD03.png

  7. At the bottom of the Single sign-on page, download the "Certificate (Base64)" from "SAML Signing Certificate". Also,
    note down the "Login URL" and "Azure AD Identifier" found in "Set up TrustLogin".

    AzureAD04.png

This completes the configuration on the Entra ID side.
Next, configure the TrustLogin side.

Configuration on the TrustLogin Side

  1. Log in to TrustLogin,
    and open "Settings > Optional Features > External IdP Integration > Settings" on the "Admin Page".
    optionlist.png
  2. Open "Add SAML IDP".
    AzureAD05.png
  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name you like.
    Example: Entra ID (Azure Active Directory)
    SSO URL Configuration on the Entra ID (Azure Active Directory) Side > The "Login URL" value noted in Step 7
    Entity ID Configuration on the Entra ID (Azure Active Directory) Side > The "Azure AD Identifier" value noted in Step 7
    SAML Identity Provider Certificate Configuration on the Entra ID (Azure Active Directory) Side > The certificate information downloaded in Step 7
    Note: Open the certificate in a text editor and copy and paste the text.
    NameID Format Specify "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress".

    Note: For details, seehere
    Preferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.

    Note: For details, seehere
    Case Sensitive Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: For details, seehere


  4. Click "Register".
  5. Next, assign the members who will log in using their Entra ID.
    From the External IdP list, click the name of the SAML IDP you just added.
  6. Click "Add Member". (To add by group, click "Add Group".)
    ______.png
  7. Select the target members and click the "Register" button.
    SKUID__11_.png

    The member addition is complete.
    This completes the configuration.

Verifying the Configuration

From the TrustLogin login page, enter your company ID and email address, and an Azure Active Directory button will appear. Click it to log in. (Only administrators can also log in using their TrustLogin password.)

SKUID02.png

How to Configure Entra ID (Azure Active Directory) External IdP Integration

This page explains how to use Entra ID (Azure Active Directory) as a SAML Identity Provider (IdP)
and configure integration with TrustLogin.

Configuration is performed on both the Entra ID side and the TrustLogin Admin Page.

Prerequisites

  • You must apply for the External IdP Integration option of TrustLogin.
  • You must create an account in TrustLogin using the same email address as in Entra ID (Azure Active Directory).
    Note: If you use the login ID for matching, the email addresses do not need to match.
     Reference: NameID Settings for External IdP (SAML) Integration
  • TrustLogin's External IdP Integration supports only SP Initiated SSO.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: We recommend that administrator users keep password authentication assigned in case of emergency.
     Reference: Configuring Password Authentication - Logging in with Both IdP and TrustLogin Passwords

Setup Procedure

Configuration on the Entra ID (Azure Active Directory) Side

Note: For the latest setup instructions, please refer to the manual provided by Microsoft.
 Reference (external site): Understand SAML-based single sign-on

  1. Open the Azure Portal.
  2. In "Entra ID (Azure Active Directory)" > "Enterprise applications", select "+ New application".
    AzureAD01.png
  3. Select "Non-gallery application", enter "TrustLogin" as the name, and click the "Add" button.
    AzureAD01.png
  4. In "Properties", set the logo. Also, change "Visible to users?" to "No" and click "Save".
    AzureAD02.png
  5. In "Users and groups", select "+ Add user". Assign the users who will use the IdP integration.
    AzureAD04.png
  6. In "Single sign-on", select "SAML-based sign-on" for the "Single sign-on mode",
    configure each item as follows, and click the "Save" button.

    Item Setting Value / Details
    Sign on URL (Optional)

    Note: External IdP integration usually supports only SP Initiated SSO,
     however, setting the following URL in the "Sign on URL" field allows you to initiate login from the IdP.
     Configure this as needed.

    https://portal.trustlogin.com/

    Identifier (Entity ID) trustlogin-saml-sp
    Reply URL (ACS URL) https://portal.trustlogin.com/saml/acs

    AzureAD03.png

  7. At the bottom of the Single sign-on page, download the "Certificate (Base64)" from "SAML Signing Certificate". Also,
    note down the "Login URL" and "Azure AD Identifier" found in "Set up TrustLogin".

    AzureAD04.png

This completes the configuration on the Entra ID side.
Next, configure the TrustLogin side.

Configuration on the TrustLogin Side

  1. Log in to TrustLogin,
    and open "Settings > Optional Features > External IdP Integration > Settings" on the "Admin Page".
    optionlist.png
  2. Open "Add SAML IDP".
    AzureAD05.png
  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name you like.
    Example: Entra ID (Azure Active Directory)
    SSO URL Configuration on the Entra ID (Azure Active Directory) Side > The "Login URL" value noted in Step 7
    Entity ID Configuration on the Entra ID (Azure Active Directory) Side > The "Azure AD Identifier" value noted in Step 7
    SAML Identity Provider Certificate Configuration on the Entra ID (Azure Active Directory) Side > The certificate information downloaded in Step 7
    Note: Open the certificate in a text editor and copy and paste the text.
    NameID Format Specify "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress".

    Note: For details, seehere
    Preferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.

    Note: For details, seehere
    Case Sensitive Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: For details, seehere


  4. Click "Register".
  5. Next, assign the members who will log in using their Entra ID.
    From the External IdP list, click the name of the SAML IDP you just added.
  6. Click "Add Member". (To add by group, click "Add Group".)
    ______.png
  7. Select the target members and click the "Register" button.
    SKUID__11_.png

    The member addition is complete.
    This completes the configuration.

Verifying the Configuration

From the TrustLogin login page, enter your company ID and email address, and an Azure Active Directory button will appear. Click it to log in. (Only administrators can also log in using their TrustLogin password.)

SKUID02.png