Skip to main content

How do I configure Single Sign-On with Azure Active Directory (Microsoft Entra ID)?

D
Written by Daria Nasedkina

This guide covers configuring SSO between Atlas and Azure Active Directory (Microsoft Entra ID). For general SSO concepts and the Atlas-side wizard in full, see How do I configure Single Sign-On (SSO)?

Step-by-step instructions

⚠ The steps below depend on how you log in — check yours before you start.

Look at the web address you use to log in:

If you log in at atlas-hub.co.uk

Step 1 – Create and configure a SAML application in Azure AD

  1. Sign in to the Microsoft Entra admin center.

    • Open the Microsoft Entra admin center in your browser.

    • Sign in with an account that has at least the Cloud Application Administrator or Application Administrator role.

  2. Create or open the enterprise application for Atlas.

    • In the left-hand navigation, go to Entra ID → Enterprise applications.

    • Create a new enterprise application for Atlas, or open the existing Atlas application if it's already set up.

    • From the application overview page, select Single sign-on.

    • On the Select a single sign-on method page, choose SAML.

  3. Configure basic SAML settings with Atlas values.

    • On Set up single sign-on with SAML, edit the Basic SAML Configuration section.

    • In Identifier (Entity ID), enter the Atlas Audience / Entity ID from the Atlas SSO configuration wizard.

    • In Reply URL (Assertion Consumer Service URL), enter the Atlas Single Sign On URL from the wizard.

    • If needed, configure any additional URLs (for example, a Sign-on URL) based on your internal Atlas setup.

    • Save the Basic SAML configuration.

    Important: Don't use generic examples from other guides. Always use the exact values generated for your Atlas environment.

  4. Download federation metadata, certificate, and URLs.

    • Still on Set up single sign-on with SAML, locate the SAML Signing Certificate or App Federation Metadata URL section.

    • Download the certificate and copy the metadata / endpoint URLs that Atlas requires (for example, the Azure IdP sign-in URL and logout URL).

    • Keep these details handy — you'll paste them into Atlas in the next step.

Step 2 – Add users in Azure AD and Atlas

  1. Add and assign users in Azure AD.

    • In the Microsoft Entra admin center, go to Entra ID → Users to create or confirm the accounts that will sign in to Atlas.

    • Return to Enterprise applications, open the Atlas enterprise application, and assign the relevant users or groups so they can use SSO.

  2. Add the same users in Atlas.

    • In Atlas, open the user management area.

    • Create or confirm user accounts that match the identifiers used in Azure AD (email address, or username for non-email users).

    • Make sure these identifiers match exactly between Azure and Atlas so that SSO can map users correctly.

Step 3 – Configure Single Sign On in Atlas

  1. Configuration name and protocol.

    • Enter a clear configuration name, for example "Azure Active Directory (Microsoft Entra ID) Single Sign On".

    • Select SAML 2.0 (or the equivalent option) as the protocol, matching what you configured in Azure.

  2. Atlas Single Sign On endpoints.

    • In the wizard step labelled Atlas Single Sign On endpoints, review the values displayed (Single Sign On URL and Audience URI / Entity ID).

    • Confirm that these values match what you entered in Azure for Identifier (Entity ID) and Reply URL.

  3. Identity provider configuration (Azure metadata, certificate, URLs).

    • In the appropriate step of the Atlas wizard, paste the Azure identity provider details you collected earlier: federation / identity provider metadata, certificate, and sign-in URL (and logout URL, if applicable).

    • Save the step after entering all required values.

  4. User attribute mapping.

    • Follow the wizard prompts to map Azure claims to Atlas user fields:

      • Map the claim containing the email address to the Atlas email field.

      • Map the claim containing the first name to the Atlas first name field.

      • Map the claim containing the last name to the Atlas last name field.

    • Phone number is not required and can be left unmapped.

    • After you complete all attribute mappings, ensure the configuration saves without errors.

Step 4 – Test the connection

Run the test from Atlas:

  • On the Atlas Single Sign On configuration page for Azure AD (Microsoft Entra ID), select Test connection.

  • Atlas redirects you to the Azure sign-in page.

Expected behaviour:

  • You're redirected to the Azure sign-in page.

  • You can successfully sign in with a user who has been assigned to the Atlas application in Azure.

  • After successful authentication, you're redirected back to Atlas.

  • Atlas shows a confirmation that the connection test was successful.

If you log in at app.ihasco.co.uk

Step 1 – Add the iHasco Training app to Azure AD / Entra ID

  1. Sign in to your Azure AD / Entra ID account.

  2. Click Enterprise Applications, then New application.

  3. Search for iHasco and click the iHasco Training tile.

  4. Click Create.

  5. Click Set up single sign on, then SAML.

  6. Edit the Basic SAML Configuration with the values in the table below, then click Save.

Note: Remember to substitute your own URL key wherever you see {url_key}.

Basic SAML Configuration field

Value

Identifier (Entity ID)

Reply URL (Assertion Consumer Service URL)

Sign on URL

Relay State

Leave empty

Logout URL

Step 2 – Create the identity provider details in Atlas

Note: Keep your Azure AD / Entra ID account open during this process — you'll need to copy and download the Azure identity provider details into Atlas.

  1. Sign in to iHasco Atlas LMS as an administrator at https://app.ihasco.co.uk/client/login.

  2. Go to Settings.

  3. Scroll down to the Advanced card and click Single Sign On.

  4. Click Add Provider and select SAML2.

  5. Type a name for this provider in Description.

  6. Scroll to IDENTITY PROVIDER DETAILS and copy the values across from Azure AD / Entra ID, using the mapping in the table below.

  7. Download the Signing Certificate from Azure AD / Entra ID and paste it into Atlas, following the certificate table below.

  8. Scroll to USER ATTRIBUTE MAPPING and enter the claim addresses from the attribute table below.

  9. Click Save, then click Enable now.

Identity provider details — what to copy where:

Copy from Azure AD / Entra ID (4 – Set up iHasco Training)

Paste into Atlas (Identity provider details)

Required

Login URL

Single Sign-on URL

Yes

Logout URL

Single Logout URL

Optional

Azure AD / Entra ID Identifier

Entity ID

Yes

Signing certificate — what to copy where:

In Azure AD / Entra ID (3 – SAML Signing Certificate)

In Atlas (Identity provider details)

Find Certificate (Base64) and click Download, then open the file in a text editor and copy all the contents.

Find X509 (Public) Certificate and paste the file contents into the box.

User attribute mapping — claim addresses:

Step 3 – Set the registration method in Atlas

  1. Go to Settings.

  2. Scroll down to the Advanced card and click Security.

  3. Find Registration Method and select Single Sign On Provider.

  4. Choose your new provider as the Selected Provider.

  5. Click Save changes.

Step 4 – Test SSO using Azure AD / Entra ID

Note: Before testing, add users to the iHasco Training application in Azure AD / Entra ID, and sign out of any iHasco administrator accounts.

  1. In your Azure AD / Entra ID account, find 5 – Test single sign-on with iHasco Training.

  2. Click Test.

If the test is successful, you'll be signed in and taken to the iHasco My Learning screen (or to the iHasco Atlas LMS if testing with a pre-registered admin account).

Troubleshooting tips

If the connection test fails:

  • Confirm that Identifier (Entity ID) and Reply URL in Azure exactly match the values shown in the Atlas Single Sign On endpoints step.

  • Check that the user is assigned to the Atlas enterprise application in Azure and that the same user exists in Atlas with matching identifiers.

  • Verify that the SAML attribute names / claims for email, first name, and last name in Azure match the mappings you configured in Atlas.

  • Review any error messages in Atlas and in the Microsoft Entra sign-in logs to identify where the problem is.

If you still can't resolve the issue yourself, see I can't resolve SSO issues, what should I do?

Did this answer your question?