Servicely Administration
...
Single Sign-on - SAML 2.0
SSO - Microsoft Entra Multitenant
6 min
overview when setting up single sign on with microsoft entra, there is also an option to use multitenanted sso this can simplify the setup of setting up multiple single sign on tenants, however, requires a level of administration to the other tenant you want to set it up with preparing servicely in servicely, you will need to create an identity provider search for identity provider in the menu, and select new select the template microsoft azure multitenant enter a name for the provider, a unique ‘client identifier’ (will auto generate), and select create this can be changed, but this will need to be noted, when setting up the microsoft side preparing azure active directory log into the azure portal and search for enterprise applications select + new application then + create your own application select non gallery application provide the name for the application, and press the create button wait for the application to be created select single sign on or set up single sign on select saml for the single sign on select edit on the ‘basic saml configuration’ form important the identity provider needs to starts with a domain that has been verified by azure such as https //servicely ai test com/idp callback?client name=azure ad mutitenant enter the values, verify the information carefully and select save in servicely copy the app identifier uri in the app entity id field switch to the application registration matching your enterprise application select properties, in the header description click on the application registration link in servicely copy the application id (uuid) select the authentication menu in the supported account types section select accounts in any organizational directory (any microsoft entra id tenant multitenant) click save select the api permissions menu then click on + add a permission select microsoft graph select delegated permissions search then select user read click the add permissions button finish servicely configuration select overview copy the application (client) id into the client id field of the servicely identity provider configuration create a new tenant in the tenants list and copy the tenant id in the tenant id field then go back to azure, copy the directory (tenant) id save the servicely configuration to add external tenants, add a new tenant in the tenants list