---
title: "Azure AD Integration"
slug: "azure-ad-integration"
updated: 2023-12-15T21:58:59Z
published: 2023-12-15T21:58:59Z
canonical: "kb.expedient.com/azure-ad-integration"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.expedient.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure AD Integration

## Prerequisites

- An active Azure account
- Global admin privileges
- OneLogin tenant with admin access

Support Note:Expedient will assist with configuring and troubleshooting from the OneLogin tenant. Client is responsible for the configuration on the Azure tenant.

## Configure Azure:

1. Open the Azure portal ([https://portal.azure.com](https://portal.azure.com)) and login as a global admin account. Under the three line menu in the top right corner click **Azure Active Directory**.
2. On the left side click **Enterprise Applications**
3. Click "**+ New Application**"
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-wgchcsj6.png)
4. Click "**+ Create your own application**"
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-u6hzgm7v.png)
5. Give it a name like "OneLogin - Expedient" and click "Integrate any other application you don't find in the gallery (Non-gallery)". Click Create. This may take a moment.
6. In the application, click **Single Sign-on** on the left side.
7. Click **SAML**in the next page. It will automatically take you to the configuration page.
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-gtayxzmn.png)

## Configure OneLogin

1. Login to OneLogin as an admin. Click **Administration** at the top of the page.
2. Mouse over **Authentication** and click **Trusted****IdPs**
3. Click **New Trust**
4. Give the trust a name e.g. "Azure AD - Expedient"
5. Scroll to the bottom and look for **SP Entity ID**
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-s1ikkrcf.png)
6. **Copy and paste this to a text editor.**

## Phase 2 of the Azure AD configuration

1. Go back into the Azure portal.
2. Click Edit next to **Basic SAML Configuration**
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-0cyfzbrg.png)
3. Configure the Entity ID with the value you copied out of OneLogin and configure the Reply URL to https://***your*******tenantname****.onelogin.com/access/idp
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-c4di5q6b.png)
4. Copy these values to a text editor:
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-w5cjjxmv.png)
5. Click **Download** next to Certificate (Base64)
  1. ![A screenshot of a computer  Description automatically generated with medium confidence](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-7jyq5wns.png)

## Finish OneLogin Configuration

1. Go back to the OneLogin admin page
2. Click **Show In Login Panel** and point the Login Icon to what the client would like to show up.
3. This is publicly available: [https://upload.wikimedia.org/wikipedia/commons/a/a8/Microsoft_Azure_Logo.svg](https://upload.wikimedia.org/wikipedia/commons/a/a8/Microsoft_Azure_Logo.svg)
4. Put the **Azure AD Identifier** in OneLogin as the **Issuer**
  1. ![A screenshot of a computer  Description automatically generated with low confidence](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-bpwzryor.png)
5. Check **Sign users into OneLogin** and **Send Subject Name ID or Login Hint in Auth Request**
6. Set the User Attribute to **Email** or **UserPrincipalName**. This is to match unique accounts between Azure AD and OneLogin.**Choosing Between Email** or **UserPrincipalName**In most cases, choosing Email is the easier choice as e-mail addresses are a unique identifier regardless of backing directory. When a user account doesn't have an e-mail address (ex. an internal admin or service account), using UserPrincipalName will provide the unique identifier.
7. Configure the **IdP Login URL** with the Login URL from earlier.
8. Leave the Logout URL blank. This allows users to log out of apps without completely logging out of Azure/Office 365.
  1. ![A screenshot of a computer  Description automatically generated with medium confidence](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-4esfth94.png)
9. Open the certificate you downloaded in a text editor and paste the full contents into the Certificate field
  1. ![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-wa346cqi.png)
10. Go back to the top and click **Enable Trusted IdP.**
11. Click **Save** to save the settings.

## Finish Azure AD configuration

1. Go back into Azure and click **Users and groups**
2. For logins to work, you need to grant users access to this application.
3. Click **+ Add user/group** and add the users who need OneLogin access.

## Testing

Users should be able to login to the OneLogin portal using the new Azure option.

![](https://cdn.document360.io/69e9f9c7-5da8-45e7-a671-4b8287f36122/Images/Documentation/azure-ad-integration-image-vnba9cun.png)
