# SAML with Microsoft Entra ID

{% hint style="info" %}
This process can only be fully achieved in collaboration with our team.&#x20;

Exact instructions are provided in the impacted sections below where this exchange of information is required.
{% endhint %}

## Create a new SAML App in Microsoft Entra ID

In order to connect your Microsoft Entra ID directory to Rely.io you need to create a dedicated App by following the steps below.

1. Log into your [Microsoft Azure Portal](https://portal.azure.com/). Please ensure you have permissions to create Enterprise Applications and configure SSO. If you don't have the necessary permissions please reach out to an Administrator.
2. In the search bar, type *Entra ID* and select ***Microsoft Entra ID*** to navigate to the correct management panel.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FPANpQFu9SBpvJEV4aiSU%2Fimage.png?alt=media&#x26;token=b439b008-1368-451f-8efc-be0983902768" alt=""><figcaption><p>Navigate to Microsoft Entra ID</p></figcaption></figure>

3. In your directory page go to ***Enterprise Applications***.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FpebltqHfG7mEfyQGEtXH%2Fimage.png?alt=media&#x26;token=6ca14568-bdb4-4fd6-a1b1-f8ee645eb8bb" alt="" width="334"><figcaption><p>Navigate to Enterprise Applications</p></figcaption></figure>

3. On the top menu bar select ***New Application*** and then ***Create your own application*****.**

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FwEReKORiIkCpFKgKdbNp%2Fimage.png?alt=media&#x26;token=5767fe50-eb7c-463c-bc73-e11dcb78e2aa" alt="" width="563"><figcaption><p>Create new application</p></figcaption></figure>

4. Now, specify the name that you would like to give to your application and select the **last option** as we want to integrate with an application you don't manage and doesn't exist in the Entra Gallery.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FFA1h7yJJddQBgcwz60LU%2Fimage.png?alt=media&#x26;token=0f248d02-87e1-46e8-80c7-f93b16e4943e" alt="" width="563"><figcaption><p>Finalize creation process</p></figcaption></figure>

4. Now that the Enterprise Application is created we can start the SSO configuration with SAML. Go to ***Single sign-on > SAML***.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FMImjARSM6wntMTVF25RI%2Fimage.png?alt=media&#x26;token=e2d02b82-1cc0-48f9-a524-02542dd4ac81" alt=""><figcaption><p>Select SAML for SSO method</p></figcaption></figure>

5. To proceed with the SSO configuration is important that you specify the ***Identifier*** and the ***Reply URL*** on the Basic SAML Configuration section. Click the Edit button and provide the following values:
   1. **Identifier (Entity ID):** `urn:auth0:relyio:<connection-name>`
   2. Reply URL (ACS URL): [`https://auth.rely.io/login/callback`](https://auth.rely.io/login/callback)

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2Fq2Qk89xWsQIkLuoqnmaZ%2Fimage.png?alt=media&#x26;token=be2ef8ac-93f9-470b-bd1d-d528c83043c4" alt=""><figcaption><p>Configure Basic SAML Configuration</p></figcaption></figure>

6. **(Optional)** On **step 2** - mapping - you can map additional properties such as ***groups.*** By default the email, full name, first name and last name are already mapped.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FDh59nuSHl0OnIOi7zzMt%2Fimage.png?alt=media&#x26;token=509fb528-97f7-4e0f-8a57-3a5603a9c546" alt=""><figcaption><p>Add group information to your SAML payload</p></figcaption></figure>

7. Now we need to gather some information to provide Rely.io's team for configuration on their side. Start by downloading your certificate in `.pem` format. \
   \
   On step 3, click on **Edit**, then select the three dots next to the Active certificate and down the PEM certificate.&#x20;

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FInhWp22CWA0lSXWyWpwa%2Fimage.png?alt=media&#x26;token=89bcf243-ed88-4b81-a4df-44e5cb8f779c" alt=""><figcaption><p>Download .pem certificate</p></figcaption></figure>

7. Then, copy the Login URL and store it somewhere safe.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2F4IwfWZG9J4TZrTreO0zR%2Fimage.png?alt=media&#x26;token=a2514584-a043-48d2-9684-5faf2a3914bf" alt=""><figcaption><p>Copy Login URL</p></figcaption></figure>

8. **Send the SSO URL and Certificate to Rely.io** via one of the following means:
   1. Direct outreach to your dedicated Customer Success Manager
   2. In Slack via your Dedicated Channel (for Enterprise customers)
   3. Via your in-product chat bot
   4. Via email to <support@rely.io>
9. You will receive in return a confirmation once all configurations are done on Rely.io's side.
10. Once you get the confirmation,  move to the final step of the wizard to test that the configuration worked.

<figure><img src="https://1179008450-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F1eBCWu9rFSzq3ahnNrmL%2Fuploads%2FS53zBIQbt7toY2pn2aIS%2Fimage.png?alt=media&#x26;token=1b586853-45f3-45be-ae7f-fe24adfda1a2" alt=""><figcaption></figcaption></figure>

That's it! You're SAML Connection to Rely.io from Microsoft Entra ID is now ready for your users to use.
