# Set up SSO with Microsoft Entra ID

> Connect Microsoft Entra ID (Azure AD) to Privatus Analytics with SAML 2.0 single sign-on, step by step: enterprise app, claims, certificate and testing.

1. In the Entra admin center go to **Identity → Applications → Enterprise
   applications → New application → Create your own application**. Name
   it "Privatus Analytics" and choose "Integrate any other application you
   don't find in the gallery".
2. Open **Single sign-on → SAML** and edit **Basic SAML Configuration**:

   | Entra field | Value |
   |---|---|
   | Identifier (Entity ID) | `https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_…` |
   | Reply URL (ACS URL) | `https://privatusanalytics.com/users/auth/saml/callback` |

3. Under **Attributes & Claims**, set **Unique User Identifier (Name ID)**
   to `user.mail` with the format **Email address**. (If some users have
   no mailbox, use `user.userprincipalname` when it equals their email.)
4. Under **SAML Certificates**, download **Certificate (Base64)**. Under
   **Set up Privatus Analytics**, copy the **Login URL** and **Microsoft
   Entra Identifier**.
5. In Privatus Analytics, **Workspace settings → SSO → SAML**: paste the
   login URL, identifier and certificate, list your email domains, and
   save.
6. In Entra, **Users and groups**: assign who can sign in.
7. **Test** in Privatus Analytics, then **Activate**.

For provisioning, Entra's **Provisioning** tab supports SCIM: see
[SCIM](/docs/teams/scim).
