How do I set up SAML SSO with Microsoft?
In this article, you will get a step-by-step guide to setting up SAML SSO with Microsoft as the identity provider.
In this article, you will receive a step-by-step guide to setting up SAML SSO if you use Microsoft as your identity provider. If you are looking for instructions on setting up SSO login at sipgate, you can find them here.
Open the Identity section
In the first step, log in to your Microsoft account as an admin and select in the right-hand menu: Show all --> Identity .

Create application
In the Entra Admin Center, go to the right-hand menu, select Applications and then click on Create your own application.

After a new window has opened on the right-hand side, you can enter any name that should sipgate be included. The remaining settings can be left unchanged at the default settings. Finally, click the Create.

Choose SSO method
The sipgate application has been created successfully. You can find it under Applications --> Overview . In the next step, go to Set up SSO.

Click under Select SSO method to SAML.

Transfer IdP data
In the next step, you will receive an overview of the setup steps as well as all required data for configuring the SSO setup at sipgate. This data includes the SSO URL, which Entity ID and the certificate.
To transfer this data to your sipgate account, go to point 4 in the overview Set up sipgate and copy the following information: the Login URL (SSO URL) and the Azure AD identifier (Entity ID).

Enter certificate
In point 3 SAML certificates proceed as follows: Click on Edit and select SAML signing certificate. Then open the certificate's context menu and download the Base64 certificate download it.

Open the certificate with the default text editor (file with the extension '.cer'). Copy the certificate text from the editor and paste it into sipgate under certificate .
Enter SP data
Go to point 1 Basic SAML configuration and click Edit. Enter the following data from the SSO area in sipgate (service provider data): Entity-Id --> Entity ID and ACS URL --> Reply URL (Assertion Consumer Service URL) and click Save.

Assign users
In the next step, go to the left navigation menu and select Users and groups --> Add user/group .

To select specific users or groups for SSO use, click under Users and groups to None selected.

Here you have the option to select the groups or users for your SSO application.

In the final step, click Assign.

Enable SSO at sipgate
Once you have successfully completed these steps, the interface between sipgate and Microsoft should be set up. You can then activate SSO login using the toggle at sipgate.

Errors and solutions
Last updated

