Integrate an external identity provider for an Entra ID verified domain

Shayan Sarkar 25 Reputation points
2026-01-08T14:24:19.25+00:00

I am trying to set up an external IdP as the authentication mechanism for a domain in my Entra domain, and I am running into some issues, and wanted to validate the steps.

What I would like to do is set up a domain <user_name>@test.example.com that would be one of the custom domain names within my account. After that, a user would be able to go to https://potal.azure.com/test.example.com and it would route them to the external IdP to authenticate before coming back into Azure.

These are the steps that I have done so far

  1. Added and verified the custom domain name, test.example.com, by adding the "MS=msXXXXXX" TXT record
  2. In External Identies I added a new external SAML Identity provider, the domain of the IdP does not match test.example.com
  3. I tried to add test.example.com as an additional domain, by adding the DirectFedAuthUrl TXT record but I receive the following error.

This domain is Microsoft Entra verified. You will need to configure cross-tenant access inbound settings for users to sign in with SAML/Ws-Fed identity provider instead of Microsoft Entra ID.

As a separate check, I added a complete separate domain "anotherdomain.example.com" to the external identity provider. I added the DirectFedAuthUrl TXT record and I was able to add it. However, since this isn't the domain I want to use for access to Azure, it isn't what I am looking for.

So my question is if I wanted to log into the azure portal for my Entra verified domain via an external SAML IdP, are the steps that I am following correct? Or is there another process I should follow?

Microsoft Security | Microsoft Entra | Microsoft Entra External ID

1 answer

Sort by: Oldest
  1. AI answer

    2026-01-08T14:24:35.5366667+00:00

    To integrate an external identity provider (IdP) for an Entra ID verified domain like test.example.com, you need to follow specific steps to ensure proper configuration. Here’s a summary of the correct process based on your description:

    1. Domain Verification: You've correctly added and verified the custom domain test.example.com using the TXT record.
    2. Adding the External IdP: When adding the external SAML IdP, ensure that the IdP is configured correctly and that you have the necessary details such as the Issuer URI and the authentication endpoint.
    3. Cross-Tenant Access: The error message you received indicates that you need to configure cross-tenant access inbound settings. This is necessary for users to sign in with the SAML/WS-Fed identity provider instead of Microsoft Entra ID. You will need to set up these settings in the Microsoft Entra admin center.
    4. DirectFedAuthUrl TXT Record: Ensure that the DirectFedAuthUrl TXT record is correctly configured for test.example.com. This record is crucial for establishing the trust relationship between your domain and the external IdP.
    5. Testing with Another Domain: Since you were able to add anotherdomain.example.com, it suggests that the configuration for external IdPs is working, but the specific settings for test.example.com need to be correctly aligned with the cross-tenant access requirements.
    6. Final Steps: After configuring the cross-tenant access settings and ensuring the correct TXT records are in place, users should be able to authenticate through the external IdP when accessing the Azure portal via https://portal.azure.com/test.example.com.

    If you continue to face issues, reviewing the specific configurations of the external IdP and the cross-tenant access settings will be essential. You may also want to consult the Microsoft documentation for detailed steps on configuring SAML/WS-Fed identity providers and cross-tenant access.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.