SSO setup — Microsoft Entra ID with Allocadia

Allocadia integrates with Microsoft Entra ID via SAML 2.0. Here's the setup overview and the pieces each team owns.


Prerequisites

  • Your Entra ID tenant with admin access.
  • An Allocadia tenant on a version that supports SAML 2.0 (standard for modern accounts).
  • An Allocadia admin to coordinate the SP-side configuration.
  • An HTTPS endpoint on both sides (SAML over plain HTTP is not supported).

Setup overview

The high-level flow:

  1. Create a SAML enterprise application in Entra ID for Allocadia.
  2. Download or copy Entra ID's SAML metadata (Entity ID, SSO URL, signing certificate).
  3. Provide Allocadia Support with the Entra ID metadata — we configure Allocadia as the Service Provider (SP) to trust Entra ID as the Identity Provider (IdP).
  4. Allocadia provides SP metadata back — SP Entity ID, ACS URL, logout URL — which you register in the Entra ID application.
  5. Map SAML attributes — Allocadia expects specific attribute names (email, NameID, optional group memberships). Attributes are case-sensitive.
  6. Assign users or groups to the Entra ID app.
  7. Test with a pilot user before rolling out broadly.

Allocadia Support typically runs this setup end-to-end — contact Support to kick off a project.

Required SAML attributes

The exact attribute set your account needs depends on configuration, but typically:

  • NameID — the user identifier, usually the email address.
  • Email — the user's email, used for matching against Allocadia user records.
  • Groups — optional, used for group-based access provisioning.

Attribute names and values are case-sensitive. Mismatches cause silent authentication failures.

Common pitfalls

  • Email mismatch between Entra ID and Allocadia user records. Fix: standardize the format on both sides.
  • Certificate expiration. Entra ID signing certificates rotate periodically. See SSO login to Allocadia fails after our IdP certificate was rotated.
  • Attribute name case. email is not Email.

Prevention and maintenance

  • Notify Allocadia Support a week before any scheduled Entra ID cert rotation — we can stage the new cert in advance.
  • Review the Entra ID app configuration annually for upcoming cert expirations.

Related articles

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.