Below are the recommended steps to configure SAML SSO between Microsoft Entra ID (Azure AD) and SINAI.
1. Create a new Enterprise Application
Go to the Azure Portal: https://portal.azure.com
Navigate to Microsoft Entra ID
From the left sidebar, select Enterprise Applications
Click + New application
Select + Create your own application
Enter a name (e.g., SINAI SSO)
Select Integrate any other application you don't find in the gallery (Non-gallery)
Click Create
2. Configure SAML SSO
In your new application, go to Single sign-on
Select SAML
3. Configure Basic SAML Settings
Click Edit in the Basic SAML Configuration section
Enter the values provided by SINAI:
Identifier (Entity ID) → provided by SINAI
Reply URL (Assertion Consumer Service URL) → provided by SINAI
(Optional) Add:
Sign-on URL → SINAI login page (if provided)
Click Save
4. Configure User Attributes & Claims
In the Attributes & Claims section, click Edit
Ensure the following mappings exist:
SINAI Attribute | Azure Attribute |
user.mail or user.userprincipalname (depending on account configuration) | |
given_name | user.givenname |
family_name | user.surname |
Click Save
⚠️ Note: The email value must match the user’s SINAI account email.
5. Download Identity Provider Metadata
In the SAML Signing Certificate section
Copy the App Federation Metadata URL
OR
Click Download next to Federation Metadata XML
➡️ You will share this with SINAI in a later step.
6. Assign Users or Groups
From the left sidebar, select Users and groups
Click + Add user/group
Select the users or groups who should have access to SINAI
Click Assign
⚠️ Users must be assigned to the application to use SSO.
7. Send Metadata to SINAI
Provide SINAI with one of the following:
Metadata URL (preferred)
Metadata XML file
SINAI will use this to complete the trust configuration.
8. Test SSO
In Azure, go to Single sign-on → Test
Or navigate to the SINAI login page and attempt login via SSO
During testing, verify:
Successful login flow
Correct user attributes passed
Correct email matching existing SINAI user
9. Enable SSO
Once testing is successful, SINAI will enable SSO for your organization.
Notes & Best Practices
Ensure users already exist in SINAI before testing
If using multiple domains, confirm with SINAI which domains are enabled
Keep at least one non-SSO admin login as backup during rollout
Coordinate testing with SINAI to quickly resolve any issues
