To configure a SAML SSO application in Microsoft Entra ID, the standard pattern is:
- Configure Microsoft Entra SSO
- Sign in to the Microsoft Entra admin center (https://entra.microsoft.com) as at least a Cloud Application Administrator.
- Go to Entra ID → Enterprise applications and open the application you want to configure (for example, “Vtiger CRM (SAML)” or “OutSystems Microsoft Entra ID”).
- Under Manage, select Single sign-on.
- On Select a Single sign-on method, choose SAML.
- On Set up Single Sign-On with SAML, select the pencil icon for Basic SAML Configuration and enter the values provided by the application vendor:
- Identifier (Entity ID) – typically a URL specific to the app.
- Reply URL (Assertion Consumer Service URL) – where the SAML response is posted.
- Sign-on URL – used for SP-initiated sign-in if required.
- Download and share SAML metadata / certificate with the app
- Still on the SAML configuration page, in SAML Signing Certificate, download the Federation Metadata XML or certificate as required by the app.
- Provide this metadata/certificate and the Microsoft Entra endpoints (from the Set up <App Name> section) to the application side so they can configure their SAML settings.
- Configure SSO on the application side
- In the target application’s admin console, configure SAML/SSO using the Microsoft Entra details:
- Issuer/Entity ID from Microsoft Entra.
- SSO URL / Login URL from Microsoft Entra.
- Upload the SAML signing certificate or metadata.
- Map the user identifier (often UPN or email) so it matches the Microsoft Entra user.
- Create and assign a test user in Microsoft Entra ID
- Create a test user (commonly named B.Simon in documentation) following the “create and assign a user account” quickstart.
- Assign this user to the SAML application under Enterprise applications → Users and groups so they are allowed to sign in.
- Create the corresponding user in the application
- In the application, create a user account that matches the Microsoft Entra user (same username/UPN/email) so SSO can map identities correctly.
- Test SSO
- Use the Test button on the SAML configuration page in Microsoft Entra, or initiate sign-in from the application (SP-initiated) or from My Apps / Entra portal (IdP-initiated).
- Verify that the user is signed in without being prompted for application credentials.
This pattern applies across SAML apps such as OutSystems, Vtiger CRM (SAML), Citrix Cloud SAML SSO, and others: configure SAML in Entra, configure SAML in the app with Entra metadata, create/assign a test user in Entra, create a matching user in the app, then test SSO.
References: