Our SAML SSO integration uses a self-setup model that allows you to set up, manage, and edit your SAML integration in the Acquia DAM.
First, the SAML Integration feature must be enabled in Acquia DAM in order to configure SAML settings and set up SAML SSO with Microsoft Entra ID (formerly Azure Active Directory). See our general SAML setup instructions for how to enable the feature.
Use the instructions below to integrate Microsoft Entra ID after the SAML feature is enabled.
Service Provider info
The Issuer/Entity ID is a unique string that identifies the provider issuing a SAML request. It will display during AuthnRequests and within SP metadata. You can customize the end of the value. You can also edit the Name ID Format value. For the registration code field, select a SAML-specific registration code and save. If you have not set one up yet, learn how to create registration codes, then contact your account rep or DAM Customer Support to lock your code as SSO-only.
The remaining fields cannot be edited.
You can export all of the information from the SP tab into a single file that you can upload into Microsoft Entra ID. To do this, select Download under SP Metadata from the SP tab, then navigate back to Microsoft Entra ID. Click Upload metadata file and select the file from your computer.
You can also manually enter the SP information into Microsoft Entra ID instead. In Microsoft Entra ID, edit section one, Basic SAML Configuration, using the corresponding information in the SP tab of the Acquia DAM.
Attributes
In section two, Attributes & Claims, under Required Claim, configure the Unique User Identifier (Name ID) to match the format of the Name ID Format found on the Acquia DAM SP tab. By default, email, first name, and last name attributes are required by the Acquia DAM. Add each of those attributes into Microsoft Entra ID, then select its respective value in the corresponding dropdown. The attribute names you create must match the names in the Attributes tab in the Acquia DAM SAML settings.
Certificates
In section three, SAML Certificates, download the Certificate (Base64) file. Go to the Identity Provider (IdP) tab in the Acquia DAM SAML settings. In the Certificate Files section, upload the Certificate (Base64) file.
Identity Provider info
In section four, Set up Acquia DAM test, copy the Login URL. Navigate to the Identity Provider (IdP) tab in the Acquia DAM SAML settings. Paste the URL in the Authorization Endpoint field. In the Support Email field, enter an email address users can contact if they have issues authenticating into the system. Click Save.
In section five, Test single sign-on, test that SAML SSO is working by logging in through IdP-initiated authentication. To do this, click Test and sign in using a Microsoft Entra ID user account that has access to the Acquia DAM enterprise application. You can also test SP-initiated authentication by visiting the SP-initiated URL, found in the Acquia DAM SAML settings SP tab. We recommend testing it in an incognito window.
Finally, to add a button for SP-initiated login to your DAM login page, follow the instructions from our SSO setup article.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Mon Aug 11 2025 12:40:06 GMT+0000 (Coordinated Universal Time)