Skip to main content
This guide connects a Microsoft Entra ID tenant to Console with SAML 2.0, so users sign in with their Microsoft account. It keeps the default claims Entra creates for a new application. Console identifies each user by their Entra object ID, so later changes to their email or name never break the link. Two people are involved:
  • Entra administrator: creates the Enterprise Application and assigns users. Needs the Cloud Application Administrator role or higher.
  • Console administrator: creates the SAML Social Application in the Console admin (Django admin → Social applications).
<company-slug> is the company name in slug form., as it appears in the company’s Console login URL (for example entraid-sso-demo)

The rest of this guide writes these as <console-host>, <client-id>, <tenant-id> and <app-id>.

Prerequisites : enable SSO on the Console instance

SSO sign-in only works once the instance-wide config key SSO is True. A Console instance administrator sets these keys in the Console admin, under Config key values (authentication category): Company settings, in the Console admin under Companies:
  • Auto provision external users: turn on together with SSO_LDAP_SIGNUP to create accounts automatically.
  • Login method: set to Single Sign On to require SSO and block password sign-in for the company’s users. Leave it on Password while you test.
Each company needs exactly one Console SSO application. The company login page is found from the company name in slug form, and two applications for the same company make it return the same “not found” error.

Step 1 : Create the Enterprise Application in Entra

  1. In the Microsoft Entra admin center, go to Identity → Applications → Enterprise applications.
  2. Click New application → Create your own application.
  3. Enter a name, for example Console SSO Demo, and choose Integrate any other application you don’t find in the gallery (Non-gallery). Click Create.
  4. In the new application, open Single sign-on and choose SAML.
Entraid Saml 1a Entraid Saml 1b

Step 2 : Basic SAML Configuration

On the SAML page, edit Basic SAML Configuration and set: Save. Leave SAML Certificates as they are: Console reads the signing certificate from the federation metadata URL. Entraid Saml 2a

Step 3 : Attributes & Claims

Keep the defaults Entra creates for a new application. Don’t add, rename or delete claims. Entraid Saml 3a Entraid Saml 3b Entra adds objectidentifier (with tenantid, identityprovider and authnmethodsreferences) to every token automatically. You don’t need to configure it.
Check user emails. Entra omits a claim whose source attribute is empty.
If a user’s Email (mail) is blank, Console falls back to the Name ID (the UPN).
Make sure each user’s mail or UPN is the address they use in Console: Users → the user → Properties → Contact information → Email.

Step 4 : Collect the Entra values and assign users

The Entra administrator sends these two values from the SAML page to the Console administrator: Entraid Saml 4a Copy the Microsoft Entra Identifier exactly, including the trailing slash. Then assign who may sign in: Users and groups → Add user/group.
A user who isn’t assigned gets an Entra error (AADSTS50105) before reaching Console.
Entraid Saml 4b

Step 5 : Configure the Social Application in Console

In the Console Django admin, open Social applications → Add and fill in: Set Settings to the JSON below, replacing the placeholders:
Entraid Saml 5a
The admin form checks only sp.entity_id and idp.entity_id. A typo in a claim name saves without an error and leaves that field empty, so copy the claim names exactly.
Account creation. On first sign-in, Console links the user to an existing account with the same email in this company.
To create missing users automatically, enable both the instance config key SSO_LDAP_SIGNUP and the company’s Auto provision external users setting.
Otherwise, create or invite users before they sign in.

Step 6 : Test the sign-in

  1. In Entra, open Single sign-on → Test this application and sign in as an assigned user.
  2. In a private browser window, open the Console login page, https://<console-host>/login, click on SSO d'entreprise, write slugified company name (My Company would become my-company) then click on Continuer to arrive on the dedicated company SSO login page. Click on Se Connecter to start the login process with EntraID.
Entraid Saml 6a Entraid Saml 6b Entraid Saml 6c
As you can see, the button to start the SSO authentication is the one you put as login URL in the SSO configuration in EntraID.
What happens on a user’s first sign-in: Later sign-ins match on the Entra object ID, not the email.

Debugging advice

If sign-in still fails, SAML-tracer shows what your browser exchanges with Microsoft and Console. It’s a free browser extension, and you don’t need admin rights to use it. Image Record a sign-in
  1. Click the SAML-tracer icon in your browser toolbar to open its window.
  2. In your main browser window, open https://<console-host>/<company-slug>/login and sign in with Microsoft.
  3. In SAML-tracer, select the rows tagged SAML and open the SAML tab to read each message.
What to check Sharing the recording with support Still stuck? Use SAML-tracer’s Export button and send the file to LightOn support with a short description of the problem. A recording contains personal and security data: the user’s email and name, a signed sign-in message from Microsoft, and possibly session cookies. Handle it like a password:
  • Record with a test account when you can.
  • In the export dialog, choose to mask or remove cookie values.
  • Send it only to LightOn support, through your usual support channel. Never post it in a public forum, a shared chat or a ticket that other people can read.
  • After recording, sign out of Console and delete the file once the issue is resolved.