Azure AD (Entra)

This article gives the steps to configure Active Directory as the identity provider for NocoDB.

NocoDB, Retrieve SAML SSO Configuration details

  1. Go to Account Settings.
  2. Select Authentication (SSO).
  3. Click the New Provider button.
  4. In the dialog, type a Display name for the provider. The login page shows the provider with this name.
  5. Copy the Redirect URL & Audience / Entity ID. You need these values later to configure the identity provider.

SAML SSO Configuration SAML SSO Configuration SAML SSO Configuration

Azure AD, Configure NocoDB as an Application

  1. Sign in to your Azure account. Go to Microsoft Entra admin center > Identity > Enterprise applications.
  2. Click + New application.
  3. On the Browse Microsoft Entra Gallery page, in the navigation bar, select Create your own application.
    • Type a name for your application.
    • Select Integrate any other application you don't find in the gallery (Non-gallery).
    • Click Create.
  4. On your application page, go to Manage > Single sign-on > SAML.
  5. Below Set up Single Sign-On with SAML, go to the Basic SAML Configuration section and click Edit.
    • Below Identifier (Entity ID), add the Audience URI.
    • Below Replay URL (Assertion Consumer Service URL), add the Redirect URL.
    • Click Save.
  6. In the Attributes & Claims section, click Edit.
    • Edit the "Unique User Identifier (Name ID)" claim:
      • From the Name identifier format dropdown, select Email address.
      • For the Source, select Attribute.
      • In the Source attribute, select user.mail.
      • Click Save.
  7. Go to the SAML Certificates section. Copy the App Federation Metadata URL.
  8. On the application's Overview page:
    • Click Users and groups.
    • Add the users or groups that need access to the application.

NocoDB, Configure Azure AD as an Identity Provider

  1. Go to Account Settings > Authentication > SAML.
  2. Enter the Metadata URL from the step above. You can also configure the XML directly.
  3. Click Save.

SAML SSO Configuration

Users now see the Sign in with <SSO> option on the sign-in page.

SAML SSO Configuration

Post sign-out, refresh page (for the first time) if you do not see Sign in with SSO option

For more common questions and troubleshooting, see our SSO FAQ.

Availability

  • SAML SSO is available on NocoDB Cloud (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach out to sales team.
  • On the Business plan, the SSO configuration menu is in the workspace sidebar, at Settings > Single Sign-On (SSO). For more details, refer here.
  • Domain Verification Required for Cloud Plans: Verify your domain in NocoDB before you configure SAML SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see Domain Verification.

Last updated on

Latest product updates?See Changelog
Stay in the loop? Follow us onLinkedInLinkedInYouTubeYouTubeXX