Microsoft Entra ID
Step-by-step instructions for configuring Microsoft Entra ID as a SAML identity provider for PostGrid SSO.
This guide explains how to configure Microsoft Entra ID (formerly Azure Active Directory) as the identity provider for PostGrid Single Sign-On (SSO).
Prerequisites
Section titled “Prerequisites”Before you begin, make sure you have:
- An active PostGrid account on a paid plan
- Administrator access to the Microsoft Entra admin center
- The PostGrid SSO values for your organization
Step 1: Create the enterprise application
Section titled “Step 1: Create the enterprise application”- Open the Microsoft Entra admin center.
- Go to Identity → Applications → Enterprise applications.
- Select + New application.
- Select + Create your own application.
- Enter a name for the application, such as PostGrid SSO.
- Select Integrate any other application you don’t find in the gallery (Non-gallery).
- Select Create.
Step 2: Configure SAML SSO
Section titled “Step 2: Configure SAML SSO”-
In the application’s left navigation, select Single sign-on.
-
Select SAML.
-
In the Basic SAML Configuration section, select Edit.
-
Enter the values provided by PostGrid:
- Identifier (Entity ID): PostGrid-provided value
- Reply URL (Assertion Consumer Service URL): PostGrid-provided value
-
Leave Sign on URL, Relay State, and Logout URL blank unless PostGrid provided specific values for them.
-
Select Save.
Step 3: Configure attributes and claims
Section titled “Step 3: Configure attributes and claims”In the Attributes & Claims section, select Edit and verify the following:
- The default Name ID uses the user’s email address as the unique identifier.
- Claims for the user’s email address, first name, and last name are included.
Use the claim names and source attributes provided by PostGrid for your configuration. If you do not have those values, confirm them with your PostGrid contact before completing setup.
Step 4: Get the certificate and identity provider URLs
Section titled “Step 4: Get the certificate and identity provider URLs”- Return to the application’s Single sign-on page.
- In the SAML Certificates section, download the Certificate (Base64).
Entra ID normally downloads this certificate as a
.cerfile. Rename the file to use a.certor.pemextension before sending it to PostGrid. - In the Set up [PostGrid SSO] section, copy:
- Login URL
- Microsoft Entra Identifier
Step 5: Assign users and groups
Section titled “Step 5: Assign users and groups”- In the application’s left navigation, select Users and groups.
- Select + Add user/group.
- Select the users or groups who should have access to PostGrid.
- Select Assign.
Step 6: Send the configuration to PostGrid
Section titled “Step 6: Send the configuration to PostGrid”Send the following information to your PostGrid contact:
- The Login URL (Entra ID SSO URL)
- The Microsoft Entra Identifier (issuer)
- The Certificate (Base64) file
- The email domain or domains to scope to SSO
After PostGrid configures the connection, existing users can sign in through the PostGrid SSO login page. New users must first sign up through the SSO signup page or accept an SSO invitation from their organization’s owner. Existing PostGrid users must first migrate their accounts to SAML SSO by signing in with their password and selecting Switch to SSO in Settings.