> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md).

# Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0

This topic provides specific instructions for using Microsoft Entra ID (formerly Azure AD) to authenticate your Cortex XSOAR users. As Microsoft Entra ID is third-party software, specific procedures, and screenshots may change without notice. We encourage you to also review the [Microsoft Entra ID documentation](https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/add-application-portal-setup-sso).

To configure SAML SSO in Cortex XSOAR, you must be a user who can access the Cortex XSOAR tenant and have either the Account Admin or Instance Administrator role assigned.

The following video is a step-by-step guide configuring SSO in Cortex XSOAR (specific Microsoft Entra ID instructions begin at minute 12:42).

Play

![Vimeo](https://f.vimeocdn.com/p/images/crawler_logo.png)

<details>

<summary>Task 1. Configure Microsoft Entra ID Security Groups</summary>

Within Microsoft Entra ID, assign users to [security groups](https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/how-to-manage-groups) that match the user groups they will belong to in Cortex XSOAR. Users can be assigned to multiple Microsoft Entra ID groups and receive permissions associated with multiple user groups in Cortex XSOAR. Use an identifying word or phrase, such as Cortex XSOAR, within the group names. For example, Cortex XSOAR Analysts. This allows you to send only relevant group information to Cortex XSOAR, based on a filter you will set in the group attribute statement.

</details>

<details>

<summary>Task 2. Copy Single SSO and Audience URI Values from Cortex XSOAR</summary>

1. In Cortex XSOAR go to Settings & Info → Settings → Access Management → **Authentication Settings**.
2. In the **Login Options** tab, toggle **SSO Disabled** to on.

   By default, SSO is disabled in Cortex XSOAR.
3. Expand the **SSO Integration** settings.
4. Copy and save the values for **Single Sign-On URL** and **Audience URI (SP Entity ID)**.

   Both values are needed to configure your IdP settings.

   You cannot save the enabled SSO Integration at this time, as it requires values from your IdP.

</details>

<details>

<summary>Task 3. Configure Cortex XSOAR Application in Microsoft Entra ID</summary>

1. From within Microsoft Entra ID, create a Cortex XSOAR application and **Edit** the **Basic SAML Configuration**.

   ![Azure-Basic-SAML-8.png](/files/8UK6A4xy5aohuaeyDuaY)
2. Paste the **Single sign-on URL** and the **Audience URI (SP Entity ID)** that you copied from the Cortex XSOAR SSO settings. The **Single sign-on URL** from Cortex XSOAR should be pasted in the **Reply URL** and the **Sign on URL** fields. The **Audience URI (SP Entity ID)** value from Cortex XSOAR should be pasted in the **Identifier (Entity ID)** and **Relay State** fields. This allows users to log in to Cortex XSOAR directly from Microsoft Entra ID.

   ![azure-basic-saml.png](/files/BH87iUzPyTxPQbjsvL6T)
3. In the **SAML Certificates** section, click **Edit** and verify that Microsoft Entra ID is configured to sign both the response and the assertion.

   ![Azure-Sign-Certificate-8.png](/files/56cr9DHGD9OymTURi2AW)
4. To have Microsoft Entra ID send group membership for the user in the SAML token, you must **+ Add a group claim** in the **Attributes & Claims** section. Send the **Security groups**, using the source attribute **Group ID**. Use the word or phrase you selected when configuring Microsoft Entra ID security groups (such as Cortex XSOAR) to create a filter. Customize the name of the group claim as **memberOf**.

   ![Azure-memberof-Group-8.png](/files/QZlUfj3NOcmQoE7QbnQP)
5. In addition to group membership, verify that there are also claims for:
   * Email address
   * First Name
   * Last Name

</details>

<details>

<summary>Task 4. Copy Login URL, Microsoft Entra ID Identifier, and Attribute Claims</summary>

1. In Microsoft Entra ID, from the **Single sign-on** page, in the **Set up Cortex XSOAR Production** section, copy the values for the **Login URL** and **Microsoft Entra ID Identifier**. You need these values to configure the SSO Integration in Cortex XSOAR.

   ![Azure-XSOAR-Settings-8.png](/files/kt7XQxZ0TNrTB20J4wAY)
2. **Edit** **Attributes & Claims** and copy the values in the **Claim name** column. The claim name is case sensitive. You need these values to configure the SSO Integration in Cortex XSOAR.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The default attributes shown on the main single sign-on page in Microsoft Entra ID are not the values you need. You must click <strong>Edit</strong> next to <strong>Attributes and Claims</strong> to view and copy the actual values.</p></div>

   ![Azure-claim-names-8.png](/files/8a2RcAKoDXmDvZKrAoPL)

</details>

<details>

<summary>Task 5. Download the Certificate</summary>

From the SAML Certificates section in Microsoft Entra ID, **Download** the **Certificate (Base64)**. You need the contents of this file to configure the Cortex XSOAR SSO Integration.

![Azure-download-certificate-8.png](/files/5xJmlQXRsnTu2AnpzrGG)

</details>

<details>

<summary>Task 6. Copy the Source IDs for Microsoft Entra ID Security Groups</summary>

The claim for the [membership attribute](https://learn.microsoft.com/en-us/entra/identity-platform/configure-saml-group-claims) that is sent to Cortex XSOAR uses the **Object Id** of the group. The **Object Id** is different from the Microsoft Entra ID security group name. You can find the **Object Id** for each of your Microsoft Entra ID security groups by navigating to **Users and groups** in Microsoft Entra ID, clicking on the group name, and viewing the **Object id**. Create a list of the group names and corresponding **Object Ids** for every Microsoft Entra ID security group you want to map to a Cortex XSOAR user group.

</details>

<details>

<summary>Task 7. Configure the Cortex XSOAR SSO Integration</summary>

1. In Cortex XSOAR go to Settings & Info → Settings → Access Management → **Authentication Settings**.
2. In the **Login Options** tab, toggle **SSO Disabled** to on.

   By default, SSO is disabled in Cortex XSOAR.
3. Expand the **SSO Integration** settings.
4. Use the following table to complete the SSO Integration settings, based on the values you saved from Microsoft Entra ID.

   | Microsoft Entra ID                           | Cortex XSOAR Field |
   | -------------------------------------------- | ------------------ |
   | Login URL                                    | IdP SSO URL        |
   | Microsoft Entra ID Identifier                | IdP Issuer ID      |
   | Contents of the downloaded certificate file. | X.509 Certificate  |
5. In the **IdP Attributes Mapping** section, enter the attribute claim names from Microsoft Entra ID. The names are case sensitive and must match exactly.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>The attribute claim name must exactly match the value sent by your IdP. In some cases, this may be the full attribute name/namespace, depending on the configuration of our IdP</p></div>

   ![Azure-XSOAR-Attributes-8.png](/files/WGJyg4btxFi5v20DxDHS)
6. (Optional) Under **Advanced Settings**, select the checkboxes for **ADFS** and **Compress encode URL (ADFS)**. In some circumstances, these fields may be required by your Microsoft Entra ID configuration.
7. Save your settings.

</details>

<details>

<summary>Task 8. Map SAML Group Memberships to Cortex XSOAR User Groups</summary>

1. Select Settings & Info → Settings → Access Management → **User Groups**.
2. Right-click a user group and select **Edit Group**.
3. In the **SAML Group Mapping** field add the Microsoft Entra ID group(s) Object Ids that should be associated with this user group. Multiple Object Ids should be separated with a comma. The Microsoft Entra ID group Object Id must match the exact value sent in the token.
4. Save your settings.
5. Repeat for each user group.

</details>

<details>

<summary>Task 9. Test SSO Login</summary>

1. Go to the Cortex XSOAR tenant URL and **Sign-In with SSO**.
2. After authentication to Microsoft Entra ID, you are redirected again to the Cortex XSOAR tenant.
3. When logged in, validate that you have been assigned the proper roles.

   To view your role and any role assigned to a user group you are a member of, click your name in the bottom left-hand corner, and click **About**.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xsoar-8-on-prem/8.9/configure-cortex-xsoar/users-and-roles-management/set-up-authentication/set-up-microsoft-entra-id-as-the-identity-provider-using-saml-2.0.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
