> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anny.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft SAML SSO

> Set up a company login with Microsoft in anny using SAML SSO, step by step, including attribute and group mapping.

In this article, you learn how to set up a company login with Microsoft in anny.

## Setup

To set up SSO, you need to complete the following steps. Important: you must be an administrator of the Active Directory for this setup.

1. Go to Azure Active Directory
2. Create a new enterprise application via *Enterprise applications* > *New application* > *Create your own application*
3. Enter the name (e.g. anny SSO) and select "Integrate any other application you don't find in the gallery"
4. Go to *Set up SSO* or *Single sign-on*
5. Select SAML
6. Download the [metadata XML file](https://app.anny.co/organization/settings/sso?o=) from anny and upload it to Microsoft via *Upload metadata file*
7. Enable signing of the attributes
8. Define who is allowed to log in
9. Copy the app federation metadata URL and enter it in anny

Afterwards, you can test the SSO connection directly and adjust your settings if needed.

Here you find an explanation of potential error messages: [SSO Troubleshooting](/en/sso-overview)

For setting up attribute mapping, you find an article here: [Attribute Mapping](/en/attribute-mapping)

## Step-by-step visualization

Follow the screenshots to set up SSO with Microsoft.

### Create a new enterprise application

First, you need to create a new enterprise application.

![Enterprise applications overview](https://anny.intercom-attachments.eu/i/o/30918/b9ec9c95584720919a69e91f/image.png?expires=1784851200\&signature=3690b342130800b6c0e8fe2959462667f73a8bcd87e5547ad5e690375b4fe245\&req=09VmxFC2rTUh3Rr0v9tnrr%2Bb2x8gLt%2FkgbEicNrMpN0Buy%2B1yf4AbE0VigwB%0AIdXCeLfG6qyziWZkMX%2F8%0A)

![Create new application](https://anny.intercom-attachments.eu/i/o/30919/84c5ccc516757657fe33293c/image.png?expires=1784851200\&signature=d1a9014a769c6956b59c895429862b6b2bd2427ac1bcd3ca1842d783b94951be\&req=09VmxFG2rTUh3Rr0v9tnrnlBG2aZR3qziHi3lL6P751aDcxTqPZzEaIuxiat%0AuuYpB6NKOC%2B37phPLDZM%0A)

![Create your own application](https://anny.intercom-attachments.eu/i/o/30920/5dbf604fecfdbc7a5d7a32a9/image.png?expires=1784851200\&signature=76be7409177d694420060e2d29350c348fda6a574a131caf7f4536180717307d\&req=09Vmx1i2rTUh3Rr0v9tnrrHFQFmt2FdgSAJFHX%2FI326aAOSsmRQ1%2BWrzo3JW%0AKcl1XEWk8UQXnAK9%2FCkp%0A)

![Name and gallery option](https://anny.intercom-attachments.eu/i/o/30921/8f4895167545a784776da90e/image.png?expires=1784851200\&signature=e4bc7d8ddcfc8c9c1234f32ee018e5cdb79130096d382e7948a662db873998db\&req=09Vmx1m2rTUh3Rr0v9tnrsi8Ciy5ZCWJXErnfpbW5KpMxXo42CdEKhqOQT26%0AVJN5zCStq3piGmqiUf%2FF%0A)

### Set up SSO

For the application you created, you then need to set up SSO.

![Set up SSO overview](https://anny.intercom-attachments.eu/i/o/30922/e8cb4b706e2547eac5a23d96/image.png?expires=1784851200\&signature=6d7b031c9e7050b00fe139ebc9f66de4364549d8d927cc095c337a07bea3ff27\&req=09Vmx1q2rTUh3Rr0v9tnrvCDCQ4xDL67pEQWnVoZqo4bLc8ZECCu9qS9csJz%0AJLf4%2BgnfNko07XFYC6Fc%0A)

![Select SAML](https://anny.intercom-attachments.eu/i/o/30923/697daf990514de5d6e901065/image.png?expires=1784851200\&signature=d2874625516aab842e2bedbf70bc996cd747d509b89ef8e2e3003ea01f8b9d24\&req=09Vmx1u2rTUh3Rr0v9tnrnyHMJVZvp1zu5gBAQOecimsbKZlO9JxaHBtDXdQ%0AXd4%2BI691vpBAkZfl6nfg%0A)

### Upload metadata file

To apply most settings automatically, it is best to upload the metadata file.

![Upload metadata file](https://anny.intercom-attachments.eu/i/o/30924/9c2565950316e7b1c9996d4a/image.png?expires=1784851200\&signature=681efdcbbf389ee2c71c6d6dbf0756e712e5e6705da37bbf01e599a3cf83ac9b\&req=09Vmx1y2rTUh3Rr0v9tnrrvgamqFhrlbsvHN1hpwFgimsPrWK1Nhe6fa%2Bmrp%0AESEoex4jzZ1MLzSnz3Lx%0A)

### Enable signing of the attributes

For security reasons, we always verify the signature of the transmitted attributes. This is disabled by default. Under the "SAML Certificate" section, you can enable signing.

![Edit SAML certificate](https://downloads.intercomcdn.eu/i/o/2346033/0613700e6b79bbf72bfeda06/image.png?expires=1784851200\&signature=ab1771c8f68ded8a81b743d7cdb35d0df9daee23eeafcc0fc8d40965219d17d7\&req=0tZrw1j5r3sp2RPy89osp4otqxHG09cIB3ZC4a5Yx0xPnEtqAY9%2FnSA695eP%0AW1SL%2FARVZCO9jWiJJ5ZJgSc%3D%0A)

Select the settings as shown in the screenshot:

![Signing options](https://downloads.intercomcdn.eu/i/o/2346168/fe78a9095532e1cd71223bbb/image.png?expires=1784851200\&signature=465222c808bb64f9de28bfe63134a03cc0d77d3942c3dc388a3ce173bbc7b520\&req=0tZrw1n8pHsp2RPy89osp3uAfYWVor%2B9O7z934cJAL0fnoEL7Pu64bvuIcZq%0A6krzfPySfOfbJxqWWtd%2FOe8%3D%0A)

### Define who is allowed to log in

Now you still need to define who is allowed to log in to the application. Normally, all your employees should be allowed to log in. To do this, navigate to "Properties" and set the "Assignment required" option to "No".

![Set assignment required to No](https://downloads.intercomcdn.eu/i/o/2346227/ead3275fa795b4b8b52b8ae7/image.png?expires=1784851200\&signature=a7b6de59ea9d3dd2cf597ab04cccfe4ad0c32279ea952e3b628c29a22f181a17\&req=0tZrw1r4q3sp2RPy89osp6wDFBLg%2Bxrn8jGxPqWA0DdJW%2FPiIMnHlpB%2Fi81Q%0AcTeN1OGg2ePuxDgtF7KiCdk%3D%0A)

If you only want to allow specific users access, you need to set the option to "Yes" and select the users who should get access under "Users and groups".

### Copy the metadata URL and enter it in anny

Finally, copy the metadata URL and enter it in anny so the setup can be completed.

![Copy metadata URL](https://anny.intercom-attachments.eu/i/o/30925/f737b4a007b8c20eb30f37e0/image.png?expires=1784851200\&signature=748eaf3c03cababc46b56f61fa55314b57976cb45cd37f8e1d5db4d85da0877f\&req=09Vmx122rTUh3Rr0v9tnruS045Y208OXng0%2FKOATGeHvrAZd0y7K09e6fQFc%0ABqAwJU7p33EcOi2jonWP%0A)

***

### Optional: Verify the signature of the request

You have the option to have the signature of the login requests (SAMLRequest) verified. To do this, you need to upload the certificate.

First, you need to download the certificate. The URL for it is derived from the metadata URL.

Metadata URL: [**https://auth.anny.co/tenant/\{id}/saml/metadata**](https://auth.anny.co/tenant/\{id}/saml/metadata)

Certificate URL: [**https://auth.anny.co/tenant/\{id}/saml/cert**](https://auth.anny.co/tenant/\{id}/saml/cert)

You then need to upload this certificate:

![Upload certificate](https://downloads.intercomcdn.eu/i/o/2346333/e0eac70e209913a71cd3a0e2/image.png?expires=1784851200\&signature=38974f47cedd72fb16ca4c9be7d992d83734ccd1979a2192734b0498a1e76c2c\&req=0tZrw1v5r3sp2RPy89osp9zk796ccUHPtpQAkr%2BWY2e%2FYD1WhAB9htHQIe2s%0A72lxcVF0pfvn9jwCsswU4Vg%3D%0A)

![Verification certificate](https://downloads.intercomcdn.eu/i/o/2346373/7513be2008d76b11dce1b650/image.png?expires=1784851200\&signature=6dd589e03ea7c28c891032fa4d218d5f5c235bbadfc56978e221df5606bc83e5\&req=0tZrw1v9r3sp2RPy89ospztuB81%2FdZjb0V6%2Fhg6X%2BIDZzMYyJsUdC6BeL9NH%0AoLz3yeScqjNnpEz2SuuhsV4%3D%0A)

## Release groups for attribute mapping

To use groups as an additional attribute in anny for attribute mapping, this first needs to be released in Azure Active Directory. The following steps are required:

1. Go to Azure Active Directory and select the enterprise application you created.
2. Select the "Single sign-on" tab here.
3. Here you find the "Attributes & Claims" tile, click Edit here.
4. Here you can now add the attribute via the "Add a group claim" button.

![Add a group claim](https://downloads.intercomcdn.eu/i/o/4812242/9aa47be57870170cdb867bd9/image.png?expires=1784851200\&signature=0144cbcf5c757836fd9b1a3ecb4004bd16d12258f053047a4ab760af40a37f3d\&req=1N1ux1r%2Brnsp2RPy89osp%2BAirYqrHDwT6H8ivqb7MashTUjTNGO9dTjL%2FwNR%0AewUWJ4gpkOI%2FhswVyRjTgZY%3D%0A)

5. Select "All groups" there and click Save. Now the groups are also passed along as attributes and can be used in anny.

<Warning>
  **Important:** If the user is assigned to too many groups, Microsoft cannot pass them to us. This shows, for example, in the user then not being assignable through attribute mapping. The following workaround is required:

  1. When assigning groups, do not select "All groups", but the "Groups assigned to the application" option.
  2. Now, in the application under "Users & groups", you can add the groups that should be assigned to the application. This way, only the required groups are transferred to anny.
</Warning>
