Add Azure AD as a SAML provider
This guide explains how to let users sign in to Casdoor with their Azure AD (Microsoft Entra ID) account through SAML.
Learning outcomes
- Create an enterprise application for Casdoor in Azure AD.
- Add Azure AD as a SAML provider in Casdoor.
- Assign users and test the sign-in.
What you need
- An Azure AD tenant with the rights to create enterprise applications
- Administrator access to the Casdoor admin console
Create an enterprise application
- In the Azure portal, go to Azure Active Directory > Enterprise applications.
- Click New application > Create your own application.
- Enter a name, for example
Casdoor, select Integrate any other application you don't find in the gallery (Non-gallery), and click Create.
Configure single sign-on
-
In the enterprise application, go to Single sign-on and select SAML.
-
In Basic SAML Configuration, click Edit and enter:
Field Value Identifier (Entity ID) https://<your-casdoor-domain>/api/acs, for examplehttps://door.example.com/api/acsReply URL (Assertion Consumer Service URL) The same URL Azure AD sends the response with HTTP POST, which the
/api/acsendpoint requires. -
Click Save.
-
Keep the default Attributes & Claims, or change them:
Claim Default source Unique User Identifier user.userprincipalnameemailaddress user.mailname user.userprincipalnameIf no username attribute is mapped, Casdoor uses the email address or the NameID of the assertion as the username.
-
Download the Federation Metadata XML from the SAML Certificates section. Alternatively, note the Certificate (Base64) and, in the Set up Casdoor section, the Login URL, the Azure AD Identifier, and the Logout URL.
Add the provider in Casdoor
- In the Casdoor admin console, go to Identity > Providers and add a provider.
- Set Category to
SAMLand Type toCustom. - Paste the federation metadata into Metadata and click Parse.
- Save the provider.
- Open the edit page of your application, add the provider on the Providers tab, and save.
Assign users
In the enterprise application in Azure AD, go to Users and groups and assign the users or groups that may sign in to Casdoor.
Verify the result
Open the sign-in page of the application and click the Azure AD button. You can also test from Azure AD with the Test button of the SAML configuration.