Step 1: Domain verification
Step 1: Domain verification
- Click the account menu at the bottom of the sidebar, and select Settings.
- Open the SAML tab.
- In the Connection section, enter a Name for this configuration and the Domain to verify, for example
acme.com. - Click GET TXT RECORDS.
- Add the resulting TXT record to the domain’s DNS.
- Click VERIFY DOMAIN once the record has propagated. The domain’s status changes from Pending to Verified.
- Under Identity Provider, select Microsoft Entra ID from the dropdown.
Step 2: Identity provider configuration
Step 2: Identity provider configuration
- Log in to the Azure portal.
- Go to Microsoft Entra ID > Applications > Enterprise Applications > + New Application.
- Select Create your own application.
- Name the application, for example “Zenskar SSO”, and choose Integrate any other application you don’t find in the gallery (non-gallery application).
- After the app is created, go to Single Sign-On, and choose SAML.
- Copy the following values from the Azure portal into Zenskar’s Identity Provider Configuration section:
Open the downloaded certificate file in a text editor, and copy the certificate including the BEGIN CERTIFICATE header and the END CERTIFICATE footer.
- Assign the users or groups who should have access.
Step 3: Attribute mapping
Step 3: Attribute mapping
In Zenskar’s Attribute Mapping section, map each Zenskar field to the Microsoft Entra claim that carries it:
These are Microsoft’s default claim names. If the enterprise application’s claims have been customized, use the actual claim names configured under Microsoft Entra ID > Enterprise applications > [Your App] > Single sign-on > User Attributes & Claims instead.
Step 4: Add Zenskar's SAML values to Microsoft Entra
Step 4: Add Zenskar's SAML values to Microsoft Entra
- Copy the following values from Zenskar’s Zenskar SAML Configuration Values section into the Azure portal:
- Save the configuration in the Azure portal.
- Back in Zenskar, turn on SAML Status, and click Save Configuration.
Step 5: Test SSO login
Step 5: Test SSO login
- Confirm the user exists in both Microsoft Entra ID and Zenskar, with a matching email address.
- Sign out, and go to the Zenskar sign-in screen.
- Sign in using the account’s email address. With a verified domain and an enabled configuration, the sign-in should route through Microsoft Entra ID.
- On success, the sign-in returns to the Zenskar dashboard.