Paste Acquia metadata into Entra ID to finalize the SAML configuration. |
| 5 | Configure SAML attribute configuration | Map the exact first name, last name, and email attributes between Entra ID and Acquia. |
| 6 | Enable user access | Assign the necessary users or groups to the Acquia SSO enterprise application in Entra ID. |
Before you configure your Identity Provider, ensure that you add and verify your domain in Acquia SSO management console. You cannot assign an Identity Provider without a verified domain. For detailed information, refer to Adding a domain.
To create the Acquia enterprise application in Entra ID and gather the required metadata:
Sign in to Microsoft Entra admin center.
Go to Enterprise applications, select New application, and select Create your own application.
Enter a name such as Acquia SSO, select Integrate any other application you do not find in the gallery (Non-gallery), and select Create.
In the left menu of the application, go to Single sign-on and select SAML.
In the SAML Signing Certificate section, download the Certificate Base64.
In the Set up Application Name section, copy the Login URL and Microsoft Entra Identifier. Keep these values available for the next step.
For detailed information, refer to Adding an Identity Provider.
Enter a Label, select your verified Domain from the list, and paste the Microsoft Entra Identifier and Login URL.
Open your downloaded Base64 Certificate in a text editor and paste the contents into the Public certificate field.
Click Add identity provider.
The system displays the Service Provider details.
To finalize the SAML configuration in Microsoft Entra ID:
Return to your Entra ID application, go to Single sign-on, and select SAML.
In the Basic SAML Configuration section, select Edit.
In the Identifier Entity ID field, select Add identifier and paste the Acquia Entity ID.
In the Reply URL Assertion Consumer Service URL field, select Add reply URL and paste the Acquia ACS URL.
Select Save and close the panel.
Acquia SSO requires exact attribute names. You must configure Entra ID claims to match the required format of Acquia SSO.
To configure SAML attribute configuration:
In the Attributes and Claims section, select Edit.
Select Add new claim to map the required attributes exactly as written.
Name: firstName and Source attribute: user.givenname.
Name: lastName and Source attribute: user.surname.
Name: email and Source attribute: user.mail.
Ensure that the Namespace field is completely blank for all three claims.
Select Save for each claim.
To grant your organization access to the Acquia SSO app:
In your Entra ID application, go to Users and groups.
Select Add user or group and select the required users or groups.
Select Assign.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
If this content did not answer your questions, try searching or contacting our support team for further assistance.