> For the complete documentation index, see [llms.txt](https://support.docstudio.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://support.docstudio.com/admin-panel/account-settings/how-to-set-up-sso-saml-2.0-with-azure.md).

# How to set up SSO SAML 2.0 with Azure

Single Sign-On (SSO) is an authentication method that enables users to securely log in to various applications, platforms, or websites using a single set of credentials. SSO functions based on a trust relationship between a service provider application and an identity provider (IdP) such as Google, Okta, OneLogin, or Microsoft AD FS. This trust is typically established through a certificate exchanged between the IdP and the service provider:

<figure><img src="/files/Wm2GiRIjwVvjNwB0xzzh" alt=""><figcaption></figcaption></figure>

Benefits of using SSO:

* Users sign in with existing credentials. They type passwords less often.
* Your IdP stays the source of truth for authentication.
* You do not need to sync passwords with the IdP.

In DocStudio, you can configure Single Sign-On to allow employees to access DocStudio through their Identity Provider (IdP), removing the need for passwords during the login process, ensuring secure and quick access.

DocStudio's single sign-on system is based on Security Assertion Markup Language 2.0 (SAML 2.0), which is the leading industry standard for exchanging authentication and authorisation data across web applications.

{% columns %}
{% column %}
In the **'Integrraions'** tab, you can add your SSO providers to set up SSO authentication for corporate users. To **'Create an SSO provider'**, click on the corresponding button and complete the fields in the modal window:
{% endcolumn %}

{% column %}

<figure><img src="/files/CxSxmwamVGBotfsqEhRw" alt=""><figcaption></figcaption></figure>

{% endcolumn %}
{% endcolumns %}

You can choose the type of metadata (URL or XML). After filling out the details, click the <img src="/files/F0ede5xeVlYuP0oLQGBt" alt="" data-size="line"> button.

The providers added this way can be edited or deleted  (although deletion requires confirmation)

<figure><img src="/files/kLpjaLG9if4vGD5KcqUR" alt=""><figcaption></figcaption></figure>

### **Configuring on the Azure Side**

To proceed, register the application in the **Azure Active Directory (Azure AD)** with a corporate identity management administrator account.

<figure><img src="/files/i5lZ6RIrd2aYjuNhDrDk" alt=""><figcaption></figcaption></figure>

Then navigate to the menu and go to ‘Enterprise apps’ -> ‘New app’ -> ‘Create a custom app’

<figure><img src="/files/QcCApg6zZGY7qSZdr6ah" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/obtAr6afK0AzJWiEeMJW" alt=""><figcaption></figcaption></figure>

Once the application is added and visible in the ‘Enterprise apps’ list.\
\
Configure SAML (Single Sign-On options) by selecting ‘Single sign-on’ in the ‘Management’ section and then choosing SAML.

<figure><img src="/files/5tL43YTAuUqkiJPgOI6P" alt=""><figcaption></figcaption></figure>

Next, you need to configure the Single Sign-on parameters

Basic SAML Configuration

* Identifier (Entity ID) = <https://api.docstudio.com/saml/metadata>
* Response URL = <https://api.docstudio.com/saml/SSO>

<figure><img src="/files/gAqEevl0b3m3gWnCrKdB" alt=""><figcaption></figcaption></figure>

{% columns %}
{% column %}
After adding the URLs and saving the basic configuration, these settings will be available in the system:

* **Attributes and Validations**
* **SAML certificates**
  {% endcolumn %}

{% column %}

{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column width="50%" %}
You will need to configure the SSO connection in DocStudio as follows

* **First Name Match = user.givenname**
* **Surname Match = user.surname**
* **Phone number match = user.mail**

{% hint style="info" %}
These settings may vary depending on your Active Directory (AD) configuration
{% endhint %}
{% endcolumn %}

{% column width="50%" %}

<figure><img src="/files/2YzDeX46Mrb7pqRekEgc" alt="" width="311"><figcaption></figcaption></figure>
{% endcolumn %}
{% endcolumns %}

{% columns %}
{% column %}
In the **SAML Certificates** section, upload the XML file.
{% endcolumn %}

{% column %}

{% endcolumn %}
{% endcolumns %}

To finish the setup in DocStudio, select **XML** as the metadata type.

Copy the content from your Azure metadata file, paste it into the **SSO XML field**, and click the <img src="/files/F0ede5xeVlYuP0oLQGBt" alt="" data-size="line"> button.

{% hint style="info" %}
Don’t forget to enable access for your users on the Azure side and enable SSO in the Domain settings
{% endhint %}
