Single sign-on · Microsoft Entra ID

Microsoft Entra ID

Entra ID, formerly Azure AD. Of the providers we support this is the most forgiving: it publishes a metadata URL we keep reading, and it hands out several signing certificates at once, so certificate rotation happens without you telling us.

Setting it up

The step-by-step walkthrough lives in the product, at Organisation settings → Single sign-on. Use it rather than this page for the actual setup: it shows your live service provider values with copy buttons, so there is nothing to transcribe by hand.

In outline, you will:

  • Create a non-gallery application in the Entra admin center, named Stable Baseline.
  • Switch it to SAML-based sign-on.
  • Paste our identifier, reply URL and sign-on URL into Basic SAML Configuration.
  • Check the user identifier is the user’s email address.
  • Copy the App Federation Metadata Url back into Stable Baseline.

Stable Baseline is not in the Entra gallery

Microsoft has paused new gallery submissions under its Secure Future Initiative, so the supported route is “Create your own application” and choosing the non-gallery option. This is normal and nothing about the integration is different because of it.

Always use the metadata URL

Entra offers both a metadata URL and a downloadable XML file. Use the URL. We re-read it, so when Entra rotates its signing certificate we pick the new one up on our own. Paste the XML instead and you take on a manual renewal every few years.

Certificates and rotation

Entra ID
MetadataURL, which we re-read automatically
Certificate lifetimeAbout 3 years by default
Rotation stylePublishes several signing certificates at once
Do you need to do anything?Usually not

Entra supports a staged rollover: it can publish a new signing certificate alongside the current one before switching. Because we read the metadata URL and trust every signing certificate in it, we pick up the new certificate while the old one is still in use, and the switch itself changes nothing for your users.

We track the furthest-out certificate, which is what makes this invisible. During a rollover the nearest expiry may be weeks away while the new certificate is good for years — warning you then would be a false alarm.

Renewing a certificate

  • In the Entra admin center, open your Stable Baseline application, then Single sign-on → SAML Certificates.
  • Create a new certificate. Leave the existing one active for now — this is what makes the change seamless.
  • Wait for us to pick it up. We re-read your metadata daily, and the expiry date in your single sign-on settings will move once we have.
  • Activate the new certificate in Entra, then remove the old one.

If you skip the overlap

Creating a new certificate and activating it immediately, in one sitting, can break sign-in for a short window before our next daily read. Leaving both active for a day avoids that entirely.

What we will tell you

We email your owners and administrators at 60, 30, 14, 7, 3 and 1 days before the certificate expires, and daily after that. The expiry date is also shown in your single sign-on settings. Because Entra rotations are usually automatic, receiving one of these emails is worth acting on: it means the rotation has not happened yet.