# Azure AD (Entra)

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > SAML). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/saml-sso/azure-ad
Last updated: 2026-10-03

Configure Active Directory (Azure AD, Entra) as a SAML identity provider for NocoDB.

This article gives the steps to configure Active Directory as the identity provider for NocoDB.

### NocoDB, Retrieve `SAML SSO` Configuration details

1. Go to `Account Settings`.
2. Select `Authentication (SSO)`.
3. Click the `New Provider` button.
4. In the dialog, type a `Display name` for the provider. The login page shows the provider with this name.
5. Copy the `Redirect URL` & `Audience / Entity ID`. You need these values later to configure the identity provider.

<img alt="SAML SSO Configuration" src={__img0} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img2} placeholder="blur" />

### Azure AD, Configure NocoDB as an Application

1. Sign in to your [Azure account](https://portal.azure.com/#allservices). Go to `Microsoft Entra admin center` > `Identity` > `Enterprise applications`.
2. Click `+ New application`.
3. On the `Browse Microsoft Entra Gallery` page, in the navigation bar, select `Create your own application`.
   * Type a name for your application.
   * Select `Integrate any other application you don't find in the gallery (Non-gallery)`.
   * Click `Create`.
4. On your application page, go to `Manage` > `Single sign-on` > `SAML`.
5. Below `Set up Single Sign-On with SAML`, go to the `Basic SAML Configuration` section and click `Edit`.
   * Below `Identifier (Entity ID)`, add the `Audience URI`.
   * Below `Replay URL (Assertion Consumer Service URL)`, add the `Redirect URL`.
   * Click `Save`.
6. In the `Attributes & Claims` section, click `Edit`.
   * Edit the "Unique User Identifier (Name ID)" claim:
     * From the `Name identifier format` dropdown, select `Email address`.
     * For the `Source`, select `Attribute`.
     * In the `Source attribute`, select `user.mail`.
     * Click `Save`.
7. Go to the `SAML Certificates` section. Copy the `App Federation Metadata URL`.
8. On the application's Overview page:
   * Click `Users and groups`.
   * Add the users or groups that need access to the application.

### NocoDB, Configure Azure AD as an Identity Provider

1. Go to `Account Settings` > `Authentication` > `SAML`.
2. Enter the `Metadata URL` from the step above. You can also configure the XML directly.
3. Click `Save`.

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

Users now see the `Sign in with <SSO>` option on the sign-in page.

<img alt="SAML SSO Configuration" src={__img4} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* SAML SSO is available on **NocoDB Cloud** (Business plan and above) and on licensed self-hosted deployments (Business plan and above). For access, reach [**out to sales team**](https://cal.com/nocodb/sales).
* On the **Business plan**, the SSO configuration menu is in the workspace sidebar, at **Settings** > **Single Sign-On (SSO)**. For more details, refer [here](/docs/product/account-settings/authentication#business-plan).
* **Domain Verification Required for Cloud Plans**: Verify your domain in NocoDB before you configure SAML SSO. Cloud Business and Enterprise plans both need this. Only users with email addresses from verified domains can sign in with SSO. For details, see [Domain Verification](/docs/product/account-settings/authentication#domain-verification).

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/okta.md): Configure Okta as a SAML identity provider for NocoDB.
- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/auth0.md): Configure Auth0 as a SAML identity provider for NocoDB.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/ping-identity.md): Configure Ping Identity as a SAML identity provider for NocoDB.
