How to Configure Microsoft 365 (SAML Automatic Configuration)

【Single Sign-On and Multi-Factor Authentication for Office 365 with TrustLogin】

You can use Microsoft 365 SAML Automatic Configuration independently of the Microsoft 365 (Office 365) Integration.
However, since the ImmutableID user attribute is required, this feature is designed to be used together with SCIM IDP Integration.

Note: ImmutableID is set by syncing Active Directory and Microsoft Entra ID via Microsoft Entra Connect.
 If you are not planning to use this configuration, please consider using Microsoft 365 (Office 365) Integration instead.

Note: Signing in to Windows OS does not support SAML authentication by default.
 To support it, you need to enable Web Sign-in as a sign-in option for Windows OS.

https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune

 Please note that even if you enable the Web Sign-in option described above, if you are using TrustLogin's certificate authentication feature, sign-in will fail with an error because the OS certificate cannot be referenced before signing in to Windows OS.


"How to Configure SCIM IDP Integration (Microsoft Entra ID) – Support – TrustLogin byGMO [Former SKUID] (trustlogin.com)"

Note: To use this feature, you need to subscribe to the TrustLogin Pro Plan or the SCIM IDP Integration option.
For pricing, please see here


Note: The SAML-SSO of Microsoft 365 (Office 365) Integration
and Microsoft 365 (SAML Automatic Configuration) are the same feature,
and since both act on the same Microsoft Entra ID feature and interfere with each other, using them in parallel is not recommended.

Setup Instructions

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Microsoft 365 (SAML Automatic Configuration)."
    02.png

  3. Click "Register."
    03.png

  4. Configure the SAML settings. From the app settings screen, select "Enable SSO (SAML)."
    04.png

  5. Select "Next."
    05.png

  6. Log in with the Microsoft account you want to link via SAML.
    06.png

  7. Click "Accept."
    07.png

  8. Check "Consent on behalf of your organization" and click "Accept."
    08.png

  9. Select the domain for which you want to enable SSO (SAML) integration and click "Complete."
    09.png

  10. SAML-SSO is now enabled, and the selected domain is displayed in the "SSO Domain" field.
    10.png

  11. Add members. From the app management screen, select "Add Member," then select and register the target domain users who have already been linked with Entra ID.
    11.png
    12.png

  12. The app icon will appear on the My Page of users to whom the app has been assigned.
    13.png

  13. Clicking the app icon takes you to the Microsoft 365 screen.
    14.png

How to Configure Microsoft 365 (SAML Automatic Configuration)

【Single Sign-On and Multi-Factor Authentication for Office 365 with TrustLogin】

You can use Microsoft 365 SAML Automatic Configuration independently of the Microsoft 365 (Office 365) Integration.
However, since the ImmutableID user attribute is required, this feature is designed to be used together with SCIM IDP Integration.

Note: ImmutableID is set by syncing Active Directory and Microsoft Entra ID via Microsoft Entra Connect.
 If you are not planning to use this configuration, please consider using Microsoft 365 (Office 365) Integration instead.

Note: Signing in to Windows OS does not support SAML authentication by default.
 To support it, you need to enable Web Sign-in as a sign-in option for Windows OS.

https://learn.microsoft.com/en-us/windows/security/identity-protection/web-sign-in/?tabs=intune

 Please note that even if you enable the Web Sign-in option described above, if you are using TrustLogin's certificate authentication feature, sign-in will fail with an error because the OS certificate cannot be referenced before signing in to Windows OS.


"How to Configure SCIM IDP Integration (Microsoft Entra ID) – Support – TrustLogin byGMO [Former SKUID] (trustlogin.com)"

Note: To use this feature, you need to subscribe to the TrustLogin Pro Plan or the SCIM IDP Integration option.
For pricing, please see here


Note: The SAML-SSO of Microsoft 365 (Office 365) Integration
and Microsoft 365 (SAML Automatic Configuration) are the same feature,
and since both act on the same Microsoft Entra ID feature and interfere with each other, using them in parallel is not recommended.

Setup Instructions

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Microsoft 365 (SAML Automatic Configuration)."
    02.png

  3. Click "Register."
    03.png

  4. Configure the SAML settings. From the app settings screen, select "Enable SSO (SAML)."
    04.png

  5. Select "Next."
    05.png

  6. Log in with the Microsoft account you want to link via SAML.
    06.png

  7. Click "Accept."
    07.png

  8. Check "Consent on behalf of your organization" and click "Accept."
    08.png

  9. Select the domain for which you want to enable SSO (SAML) integration and click "Complete."
    09.png

  10. SAML-SSO is now enabled, and the selected domain is displayed in the "SSO Domain" field.
    10.png

  11. Add members. From the app management screen, select "Add Member," then select and register the target domain users who have already been linked with Entra ID.
    11.png
    12.png

  12. The app icon will appear on the My Page of users to whom the app has been assigned.
    13.png

  13. Clicking the app icon takes you to the Microsoft 365 screen.
    14.png