Single sign-on · Microsoft Entra ID
Microsoft Entra ID
Entra ID, formerly Azure AD. Of the providers we support this is the most forgiving: it publishes a metadata URL we keep reading, and it hands out several signing certificates at once, so certificate rotation happens without you telling us.
Setting it up
The step-by-step walkthrough lives in the product, at Organisation settings → Single sign-on. Use it rather than this page for the actual setup: it shows your live service provider values with copy buttons, so there is nothing to transcribe by hand.
In outline, you will:
- Create a non-gallery application in the Entra admin center, named Stable Baseline.
- Switch it to SAML-based sign-on.
- Paste our identifier, reply URL and sign-on URL into Basic SAML Configuration.
- Check the user identifier is the user’s email address.
- Copy the App Federation Metadata Url back into Stable Baseline.
Stable Baseline is not in the Entra gallery
Always use the metadata URL
Certificates and rotation
| Entra ID | |
|---|---|
| Metadata | URL, which we re-read automatically |
| Certificate lifetime | About 3 years by default |
| Rotation style | Publishes several signing certificates at once |
| Do you need to do anything? | Usually not |
Entra supports a staged rollover: it can publish a new signing certificate alongside the current one before switching. Because we read the metadata URL and trust every signing certificate in it, we pick up the new certificate while the old one is still in use, and the switch itself changes nothing for your users.
We track the furthest-out certificate, which is what makes this invisible. During a rollover the nearest expiry may be weeks away while the new certificate is good for years — warning you then would be a false alarm.
Renewing a certificate
- In the Entra admin center, open your Stable Baseline application, then Single sign-on → SAML Certificates.
- Create a new certificate. Leave the existing one active for now — this is what makes the change seamless.
- Wait for us to pick it up. We re-read your metadata daily, and the expiry date in your single sign-on settings will move once we have.
- Activate the new certificate in Entra, then remove the old one.
If you skip the overlap
What we will tell you
We email your owners and administrators at 60, 30, 14, 7, 3 and 1 days before the certificate expires, and daily after that. The expiry date is also shown in your single sign-on settings. Because Entra rotations are usually automatic, receiving one of these emails is worth acting on: it means the rotation has not happened yet.