Configuring Single Sign-On with Microsoft Entra
This article guides you through the steps needed to integrate Microsoft Entra ID (formerly Azure Active Directory) with CyberComply for SSO (single sign-on).
Prerequisites
- You must be logged into CyberComply as an organisation administrator for the organisation that you are configuring SSO for.
- You should be familiar with and have appropriate permissions to configure your Microsoft Entra account.
Configure SAML
CyberComply
- Navigate to your Account Summary page.
- Enable the toggle switch for Single sign-on configuration:

- Select the SAML SSO metadata - download option and save the file to your device.
Microsoft Entra
- Select Enterprise applications.
- Select New application.
- Select Create your own application.
- Provide a name for the application and verify that the (Non-gallery) option is selected. Click Create.

- Once created, select Single sign-on.
- Select SAML.

- Select Upload metadata file and upload the file you previously downloaded from CyberComply.
- This will populate the Identifier and Reply URL fields. Click Save.

- Verify in Attributes & Claims that emailaddress is included.

- Make a note of the App Federation Metadata Url. You will need this later. It will usually start with
https://login.microsoftonline.com/. - Download the Certificate (Base64) and save to your device.

The Microsoft Entra application is now configured.
CyberComply
- Paste the App Federation Metadata Url into IDP metadata URI.
- Click Upload IDP Signing certificate and select the Certificate (Base64) you previously downloaded.
- Click Save.

Assign users
CyberComply
- Add users as required to CyberComply by clicking the + icon in the Users panel.

- Provide an email address and role. Click Invite.
- The user will receive an email to complete the invitation process. They will set a username and password but will not need them when logging in via SSO.
Microsoft Entra
- Select Users and groups from the application you previously created.

- Select Add user/group and assign all required users. The email address must match the one provided to CyberComply.
Logging in
CyberComply
- Enter your email address as normal.

- Select Login using work/school account to initiate the SSO flow.
- Once authenticated the user will be returned to CyberComply and automatically logged in.
Updated on: 08/07/2024
Thank you!