Entra ID SSO
Create a Microsoft Entra ID enterprise app with SAML or OIDC and paste its metadata or issuer into Avaloi.
Create an enterprise application in Microsoft Entra ID, then paste its federation metadata URL or OIDC issuer into Avaloi. Only the Owner can save the connection.
Connect Entra ID
- Create an enterprise app. In Entra ID, add a non-gallery enterprise application. Assign the users or groups who should reach Avaloi.
- Set up SAML or OIDC. For SAML, use the Avaloi ACS
https://api.avaloi.com/auth/saml/{company}/acsand start URLhttps://api.avaloi.com/auth/saml/{company}/start. For OIDC, register a web client and copy the issuer,https://login.microsoftonline.com/{tenant}/v2.0. - Send
emailormailas the NameID. Avaloi matches on verified email. - Copy the metadata. SAML: the App Federation Metadata URL. OIDC: the issuer URL.
- Save in Avaloi. Open Company settings, then SSO. Paste the issuer or metadata URL, add your domains, and save.
- Test, then enforce. Sign in through Microsoft. When that works, turn on Enforce SSO.
Quick answers
Which {company} and {tenant} do I use?
{company} is your Avaloi company slug, from GET /v1/companies/me. {tenant} is your Entra ID tenant.
Members are stuck in a redirect loop. Turn Enforce SSO off, check the ACS, the metadata URL, and the NameID, then test again. See SSO.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.