Skip to main content

Setting up SSO with Microsoft Entra

How to set up Microsoft Entra as your IdP for Certara Cloud

Updated today
  1. Log in to Microsoft Entra and go to Manage > All applications

  2. Click New Application

  3. Since Certara Cloud is not included in the App Gallery, click Create your own application

  4. Name it “Certara Applications”

  5. Once the application is added, go to Single sign-on and select SAML

  6. In another tab, go to Certara Admin > Settings > SSO Settings and click Create under SAML SSO Configurations.

  7. In Microsoft Entra, Users and Groups must be managed by your IT department. You can fill in the following information to configure SSO with Certara:

    1. Basic SAML Configuration

      1. Copy the following fields from Certara Admin into Microsoft Entra > Single sign-on > Basic SAML Configuration > Edit:

        1. Service Provider (SP) Entity ID

        2. Service Provider (SP) Assertion Consumer Service URL

        3. click Save

    2. Attributes and Claims
      Click Attributes and Claims > Edit

      1. Add the following fields

        1. Name = objectid

        2. Source = Attribute

        3. Source attribute = user.objectid

        4. Click Save

      2. Add some additional claims for example:

      3. SAML Certificate

        1. Click Add a Certificate

        2. Click New Certificate

        3. Set the expiration date (may depend on your organization’s policy)

        4. Click Save (you may need to refresh the page)

        5. Download the Federation Metadata XML file (you may have to confirm the download)

  8. Go to Certara Admin > SSO Settings > Metadata file, click Enable SSO and upload the previous Federation Metadata XML.

  9. Under Certara Admin > SSO Settings > Map attributes, copy the attributes from Microsoft Entra, the following should be used as an example:

  10. Activate SSO Logs. Before logging in with SSO for the first time, we recommend that you activate SSO logs. Go to Logs > SSO Logs and click Activate. If you have issues logging in, you can use these logs to verify that your SAML IdP is sending the correct attributes and that you have them mapped correctly in CAD.

  11. Sign in with SSO. Open another browser in private mode (or incoginto) and test that you can sign in using SSO.

Troubleshooting

If you are having trouble signing in with SSO check the following:

  • Check that your Policies or User Groups are set up correctly in Entra.

  • Check the SSO Logs in CAD for details such as WARN or ERROR messages.

Did this answer your question?