# AZURE AD

#### Step 1 - Configure SSO in AZURE AD

* Log in to the Azure portal.
* Go to Enterprise Applications and click Add a New Application, and then click on Create your own application.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FJ6Y8VgHANUS5Jt0DVovG%2Fazure_1.png?alt=media&#x26;token=932c9f03-a75c-4fe5-b210-ffb0d56a269f" alt=""><figcaption></figcaption></figure>

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FuxjTftcES6IeYTNiuTgc%2Fazure_2.png?alt=media&#x26;token=fce2d32b-29a1-4a3a-a925-8c03e61b7802" alt=""><figcaption></figcaption></figure>
* Set the app name you want, and check the `Integrate any other application you don't find in the gallery` option, and click on Create.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2F4lC0AnWO7tcac7NQzsy1%2Fazure_3.png?alt=media&#x26;token=5639dd97-7c84-4102-81ce-f21a419600e5" alt=""><figcaption></figcaption></figure>
* On the Applications Overview page, click on the Set up single sign-on card then choose SAML as the single sign-on method.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FxUVaZYlIdMX6VqZFqIRm%2Fazure_4.png?alt=media&#x26;token=facf7553-cd68-4101-a75c-a5f58cab707d" alt=""><figcaption></figcaption></figure>
* On the `Basic SAML Configuration` section, enter the identifier and reply URL, and click on `Save`.
  * **Identifier (Entity ID)**
  * **Reply URL (Assertion Consumer Service URL)**

    <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FgXnRRGccqgq2907CYm45%2Fazure_5.png?alt=media&#x26;token=7a6f8fea-783d-4522-9ec4-62cadcc06c52" alt=""><figcaption></figcaption></figure>

    <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2F01Dg1qSy7oIis2v3aO9l%2Fazure_6.png?alt=media&#x26;token=661e2824-64df-4c8e-9dc9-12abc8feffb6" alt=""><figcaption></figcaption></figure>
* On the Attributes & Claims section, click on the Edit link.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2F1Q40wr1A0bgDgat9x6bx%2Fazure_7.png?alt=media&#x26;token=b378b05b-672c-49b3-b5da-dbbd81b90910" alt=""><figcaption></figcaption></figure>
* Copy the name and email claim attribute names.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FfvCUfIyxQRVKqOmbPTrK%2Fazure_8.png?alt=media&#x26;token=93499f78-b031-4ea5-9ea0-b3a675ffcb74" alt=""><figcaption></figcaption></figure>
* On the SAML Signing Certificate and Setup sections, download the Federation Metadata XML and copy the Login URL to be used on the CloudIO Setup page.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FLF8aawpPbiY28RDYgN0w%2Fazure_10.png?alt=media&#x26;token=6764adb4-f1eb-42a3-a7fe-64ee908bf4c0" alt=""><figcaption></figcaption></figure>
* Go to Users and Groups on the left side menu to assign the users or groups that should have access to CloudIO.

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FR3WMKQW2bZ8NNmUv4NKB%2Fazure_9.png?alt=media&#x26;token=52e018b8-e1ff-48de-b3a0-64901162eb58" alt=""><figcaption></figcaption></figure>

#### **Step 2 - Configure Azure SSO in CloudIO**

* Login to CloudIO and navigate to the settings tab.

  ![](https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FKjCHgsCDuDAElsOZr4fn%2FScreenshot%202023-04-06%20at%2011.14.51%20PM.png?alt=media\&token=f48781e8-ee8f-4da8-ad26-f5ae32fed6bc)
* Select SAML Auth provider and configure the below details from Step 1

  <figure><img src="https://754235390-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZ64BhrvkgPMyL9F3tk%2Fuploads%2FOZXbuqhbcRP56R07MPD9%2Fazure_11.png?alt=media&#x26;token=1f68348e-ea30-46a3-8958-87866f53a70a" alt=""><figcaption></figcaption></figure>

\ <br>

#### &#x20;<br>
