# Microsoft Entra IDPage 2

Go into your **Azure portal home**

1. Open the sidebar menu and click on **Microsoft Entra ID**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FcHP2EYPmcTHmLHfWxwwo%252Fentra-sso-step-1.png%3Falt%3Dmedia%26token%3D21eedb4e-acd9-40e7-87a1-8d2500f955d3&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=44a35b06&#x26;sv=2" alt=""><figcaption></figcaption></figure>
2. Click on **Add button > Entreprise application**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FhQSq80CMZRcIyPh3TTiX%252Fentra-sso-step-2.png%3Falt%3Dmedia%26token%3D8528f2b1-5c8e-4a28-a465-1ca15b01f641&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=9b2de74d&#x26;sv=2" alt=""><figcaption></figcaption></figure>
3. Click on **Create your own application**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FsWAqY2buSyov5HUVxOwb%252Fentra-sso-step-3.png%3Falt%3Dmedia%26token%3D8962295d-6b85-48dd-8125-02a79525aef0&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=90af19ff&#x26;sv=2" alt=""><figcaption></figcaption></figure>
4. Enter a name and then click **Integrate any other application you don’t find in the gallery (Non-gallery)**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FtsRDlW8OWeGkZ5A1Yugg%252Fentra-sso-step-4.png%3Falt%3Dmedia%26token%3D2fa3b826-97f5-45f1-b143-a4f1db02b673&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=a86d5b1f&#x26;sv=2" alt=""><figcaption></figcaption></figure>
5. Click on **Single sign-on** from the sidebar menu or on **Set up single sign on** bellow Getting Started and choose **SAML**

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FTqOEyhtgK3FpNb3XI3pY%252Fentra-sso-step-5-1.png%3Falt%3Dmedia%26token%3Dfb135a7c-839b-41a1-8a38-0829fdb2107f&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=1719fdf2&#x26;sv=2" alt=""><figcaption></figcaption></figure>

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252F3FSPwKykdceU9OxGjBqG%252Fentra-sso-step-5-2.png%3Falt%3Dmedia%26token%3D18b5e840-30b8-4ea6-a6ca-2b79d9a39f96&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=eea4007c&#x26;sv=2" alt=""><figcaption></figcaption></figure>
6. In the first box **Basic SAML Configuration**, specify the **Entity ID**, it has to be the same than **SP Entity ID** in CISO Assistant (see next screenshot)
7. Add the **Reply URL**: `<base_url>/api/accounts/saml/0/acs/` (for example with localhost: `https://localhost:8443/api/accounts/saml/0/acs/`)

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FZjUwAWHhahnddVce11eT%252Fentra-sso-step-6-7.png%3Falt%3Dmedia%26token%3D01614726-84bc-4192-a1ae-8ed46f331979&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=501024bd&#x26;sv=2" alt=""><figcaption></figcaption></figure>
8. In the third box **SAML Certificates**, copy the **App Federation Metadata Url** as it is the **Metadata URL** in CISO Assistant (see next screenshot)
9. In the fourth box **Set up \<App\_name>**, copy the **Microsoft Entra Identifier** as it is the **IdP Entity ID** in CISO Assistant

   <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FTexEzK031txIw2uUm1Ga%252Fentra-sso-step-8-9.png%3Falt%3Dmedia%26token%3Db1572516-ce09-41dc-98e9-41d15863e18e&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=7864d459&#x26;sv=2" alt=""><figcaption></figcaption></figure>
10. Make sure you use the same Identifier (Entity ID) that you've set earlier and appear on block 1, on CISO Assistant SP Entity ID:&#x20;

    <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FGZHS1FzeUDuurXdoEN6i%252Fimage.png%3Falt%3Dmedia%26token%3D429eee78-4f3d-4737-ac2d-2d87441ec41f&#x26;width=300&#x26;dpr=4&#x26;quality=100&#x26;sign=5d2f81ff&#x26;sv=2" alt=""><figcaption></figcaption></figure>
11. Click on **Users and groups** in the sidebar menu, and **Add user/group** to give them access to CISO Assistant with SSO. The matching key will be the email and you'll be able to grant their permissions on the applications.

    <figure><img src="https://intuitem.gitbook.io/ciso-assistant/~gitbook/image?url=https%3A%2F%2F217025809-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FUJGpmCYDFJNsz2CDasSm%252Fuploads%252FpLl77BIJIhizW9qZLE8J%252Fentra-sso-step-10.png%3Falt%3Dmedia%26token%3D98fcdb84-0c24-4870-be3a-cf30c40a0e0f&#x26;width=768&#x26;dpr=4&#x26;quality=100&#x26;sign=c8957562&#x26;sv=2" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Add a user in your application doesn't automatically create the user on CISO Assistant
{% endhint %}

***

You can now [configure CISO Assistant](https://docs.clario.jojmatic.com/~/revisions/qaWPPlV1H6c58xgGUhkr/features-focus/sso) with the **3 parameters** you've retrieved.

***
