Azure SAML SSO Integration
Budget: $3,000 – $5,000 USD
I need my existing web-based applications to sign users in through Microsoft Entra ID (Azure AD) using the SAML protocol. The applications are already in development, so the goal is to let employees keep their current usernames while gaining single sign-on from the Microsoft 365 portal and any Azure-joined device.
Scope of work
• Register each web app in Entra ID, configure the SAML settings (entity ID, reply URL, logout URL, certificate).
• Map Azure AD group or role claims to the app’s authorization model so current role-based access continues to work.
• Update the apps’ config files (or reverse proxy) with the metadata XML and signing certificate.
• Validate the end-to-end flow with a test tenant first, then the production tenant, covering fresh sign-in, token renewal, and logout.
• Provide concise hand-off documentation: screenshots of portal settings, metadata files, and a step-by-step rollback plan.
Acceptance criteria
1. User can start in Microsoft 365, click the app tile, and land in the app already authenticated.
2. Direct URL access to the app redirects to Azure AD, then back after successful sign-in.
3. Role claims arrive in the SAML assertion exactly as mapped.
4. No warnings in Azure AD sign-in logs; app logs show an authenticated principal.
5. Delivered documentation allows another admin to reproduce the setup.
I can supply current SAML service provider settings, test accounts, and access to the Azure portal. Let me know the earliest you can begin and your estimated timeframe for the cut-over once credentials are provided.
Scope of work
• Register each web app in Entra ID, configure the SAML settings (entity ID, reply URL, logout URL, certificate).
• Map Azure AD group or role claims to the app’s authorization model so current role-based access continues to work.
• Update the apps’ config files (or reverse proxy) with the metadata XML and signing certificate.
• Validate the end-to-end flow with a test tenant first, then the production tenant, covering fresh sign-in, token renewal, and logout.
• Provide concise hand-off documentation: screenshots of portal settings, metadata files, and a step-by-step rollback plan.
Acceptance criteria
1. User can start in Microsoft 365, click the app tile, and land in the app already authenticated.
2. Direct URL access to the app redirects to Azure AD, then back after successful sign-in.
3. Role claims arrive in the SAML assertion exactly as mapped.
4. No warnings in Azure AD sign-in logs; app logs show an authenticated principal.
5. Delivered documentation allows another admin to reproduce the setup.
I can supply current SAML service provider settings, test accounts, and access to the Azure portal. Let me know the earliest you can begin and your estimated timeframe for the cut-over once credentials are provided.
Related categories:
Web Security
Cloud Computing
Azure
Documentation
Security
DevOps
API Integration
Microsoft 365