Before you start
You'll need:
A Microsoft Entra ID tenant (Azure Active Directory) with permissions to configure enterprise applications and single sign-on (SSO).
Access to Atlas with permission to configure SSO.
The Atlas SSO configuration page open in a separate browser tab; you'll be copying values between the two.
Step 1: Set up a SAML app in Microsoft Entra
Sign into the Microsoft Entra admin center
Go to the Microsoft Entra admin center in your browser.
Sign in with an account that has the Cloud Application Administrator or Application Administrator role.
Create an enterprise application for Atlas
In the left navigation, go to Entra ID → Enterprise applications.
Create a new enterprise application for Atlas (or open an existing one).
From the application overview, select Single sign-on.
On the Select a single sign-on method page, choose SAML.
Configure basic SAML settings
On the Set up single sign-on with SAML page, edit the Basic SAML Configuration section.
In Identifier (Entity ID), enter the Atlas Audience or Entity ID from the Atlas wizard.
In Reply URL (Assertion Consumer Service URL), enter the Atlas SSO URL from the Atlas wizard.
Configure any additional URLs if required by your Atlas administrator.
Save the basic SAML configuration.
Important: Always use the exact values from your Atlas environment, not example values from other documentation.
Download your certificate and metadata
On the Set up single sign-on with SAML page, find the SAML Signing Certificate or App Federation Metadata URL section.
Download the certificate and copy the metadata URL or endpoint URLs that Atlas requires.
Keep these handy; you'll paste them into Atlas shortly.
Step 2: Add users in Entra and Atlas
Add and assign users in Entra
In the Microsoft Entra admin center, go to Entra ID → Users to create or confirm the accounts for users who will sign in to Atlas.
Go back to Enterprise applications, open the Atlas application, and assign the relevant users or groups so they can use SSO.
Add the same users in Atlas
In Atlas, open the user management area.
Create or confirm accounts for the same users, making sure their e-mail addresses match exactly what's in Entra.
Note: User identifiers must match between Entra and Atlas for SSO to work correctly.
Step 3: Configure single sign-on in Atlas
Open the SSO configuration page in Atlas and follow the wizard.
Name and protocol
Enter a Configuration name: for example, Microsoft Entra ID SSO.
Select SAML 2.0 as the protocol.
Atlas SSO endpoints
In the Atlas SSO endpoints step, review the values shown (SSO URL and Audience or Entity ID).
Confirm these match the Identifier (Entity ID) and Reply URL you set in Entra.
Azure identity provider details
In the relevant step of the Atlas wizard, paste the Entra details you collected earlier:
Federation metadata or identity provider metadata.
Certificate.
Sign-in URL (and logout URL if applicable).
Save the configuration step.
Map user attributes
In the attribute mapping steps, connect Entra claims to Atlas user fields:
E-mail address: Atlas e-mail field.
First name: Atlas first name field.
Last name: Atlas last name field.
Phone number: optional, can be skipped.
Confirm all required mappings are complete and save without errors.
Step 4: Test the connection
In Atlas, select Test connection on the SSO configuration page.
Atlas will redirect you to the Entra sign-in page for your tenant.
You've set things up correctly if:
You're redirected to the Entra sign-in page.
You can sign in with a user assigned to the Atlas enterprise application.
After signing in, you're redirected back to Atlas.
Atlas shows a confirmation that the connection was successful.
Troubleshooting
If the connection test fails, check the following:
The Identifier (Entity ID) and Reply URL in Microsoft Entra exactly match the values shown in the Atlas SSO endpoints step.
The user is assigned to the Atlas enterprise application in Entra and exists in Atlas with a matching identifier.
The SAML attribute names and claims for e-mail, first name, and last name in Entra match the mappings in Atlas.
Review any error messages in Atlas or the Microsoft Entra sign-in logs for further detail.
If you're still stuck, contact your internal administrator or reach out to Atlas support. Include a description of what you've tried and any error messages you've seen.
