Managing external identities to enable secure access for partners, customers, and other non-employees
To integrate an external identity provider (IdP) for an Entra ID verified domain like test.example.com, you need to follow specific steps to ensure proper configuration. Here’s a summary of the correct process based on your description:
- Domain Verification: You've correctly added and verified the custom domain
test.example.comusing the TXT record. - Adding the External IdP: When adding the external SAML IdP, ensure that the IdP is configured correctly and that you have the necessary details such as the Issuer URI and the authentication endpoint.
- Cross-Tenant Access: The error message you received indicates that you need to configure cross-tenant access inbound settings. This is necessary for users to sign in with the SAML/WS-Fed identity provider instead of Microsoft Entra ID. You will need to set up these settings in the Microsoft Entra admin center.
- DirectFedAuthUrl TXT Record: Ensure that the
DirectFedAuthUrlTXT record is correctly configured fortest.example.com. This record is crucial for establishing the trust relationship between your domain and the external IdP. - Testing with Another Domain: Since you were able to add
anotherdomain.example.com, it suggests that the configuration for external IdPs is working, but the specific settings fortest.example.comneed to be correctly aligned with the cross-tenant access requirements. - Final Steps: After configuring the cross-tenant access settings and ensuring the correct TXT records are in place, users should be able to authenticate through the external IdP when accessing the Azure portal via
https://portal.azure.com/test.example.com.
If you continue to face issues, reviewing the specific configurations of the external IdP and the cross-tenant access settings will be essential. You may also want to consult the Microsoft documentation for detailed steps on configuring SAML/WS-Fed identity providers and cross-tenant access.
References: