# Azure AD (Entra)

> Part of the NocoDB documentation (Product docs > Account & Billing > Authentication ☁ > SAML). Index of all pages: https://nocodb.com/llms.txt. Any docs page is available as Markdown by adding `.md` to its URL.

URL: https://nocodb.com/docs/product/account-settings/authentication/saml-sso/azure-ad
Last updated: 2026-09-25

Learn how to configure Active Directory as an identity provider for NocoDB.

This article briefs about the steps to configure Active Directory as Identity service provider for NocoDB

### NocoDB, Retrieve `SAML SSO` Configuration details

1. Go to `Account Settings`
2. Select `Authentication (SSO)`
3. Click on `New Provider` button
4. On the Popup modal, Specify a `Display name` for the provider; note that, this name will be used to display the
   provider on the login page
5. Retrieve `Redirect URL` & `Audience / Entity ID`; these information will be required to be configured later with the
   Identity Provider

<img alt="SAML SSO Configuration" src={__img0} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img1} placeholder="blur" />
<img alt="SAML SSO Configuration" src={__img2} placeholder="blur" />

### Azure AD, Configure NocoDB as an Application

1. Sign in to your [Azure account](https://portal.azure.com/#allservices) and navigate
   to `Microsoft Entra admin center` > `Identity` > `Enterprise applications`
2. Click `+ New application`
3. On the `Browse Microsoft Entra Gallery` page, select `Create your own application` from the navigation bar.
   * Provide your application's name.
   * Choose `Integrate any other application you don't find in the gallery (Non-gallery)`
   * `Create`
4. On your application page, navigate to `Manage` > `Single sign-on` > `SAML`
5. Go to the `Basic SAML Configuration` section under `Set up Single Sign-On with SAML` and click `Edit`
   * Add the `Audience URI` under `Identifier (Entity ID)`.
   * Add the `Redirect URL` under `Replay URL (Assertion Consumer Service URL)`.
   * Click `Save`
6. In the `Attributes & Claims` section, click `Edit`
   * Edit the "Unique User Identifier (Name ID)" claim:
     * Select `Email address` from the `Name identifier format` dropdown
     * Choose `Attribute` as the `Source`
     * In the `Source attribute`, select `user.mail`
     * Click `Save`
7. Go to the `SAML Certificates` section and copy the `App Federation Metadata URL`
8. on the Application's Overview page,
   * Click `Users and groups`,
   * Add the necessary users or groups to the application.

### NocoDB, Configure Azure AD as an Identity Provider

1. Go to `Account Settings` > `Authentication` > `SAML`
2. Insert `Metadata URL` retrieved in step above; alternatively you can configure XML directly as well
3. `Save`

<img alt="SAML SSO Configuration" src={__img3} placeholder="blur" />

For Sign-in's, user should be able to now see `Sign in with <SSO>` option.

<img alt="SAML SSO Configuration" src={__img4} placeholder="blur" />

<Callout type="note">
  Post sign-out, refresh page (for the first time) if you do not see `Sign in with SSO` option
</Callout>

<Callout type="info">
  For more common questions and troubleshooting, see our 

  [SSO FAQ](/docs/product/account-settings/authentication/FAQs)

  .
</Callout>

## Availability

* SAML SSO is available on **NocoDB Cloud** (Business plan and above) and licensed self-hosted deployments (Business plan and above). For access, please reach [**out to sales team**](https://cal.com/nocodb/sales).
* For users on **Business plan**, the SSO configuration menu is available under **Settings** > **Single Sign-On (SSO)** in the workspace sidebar. Refer [here](/docs/product/account-settings/authentication#business-plan) for more details.
* **Domain Verification Required for Cloud Plans**: Before configuring SAML SSO, you must verify your domain in NocoDB (required for both Business and Enterprise plans in the cloud). Only users with email addresses from verified domains can sign in via SSO. See [Domain Verification](/docs/product/account-settings/authentication#domain-verification) for details.

---

## Related pages

- [Okta](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/okta.md): Learn how to configure Okta as an identity provider for NocoDB.
- [Auth0](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/auth0.md): Learn how to configure Auth0 as an identity provider for NocoDB.
- [Ping Identity](https://nocodb.com/docs/product/account-settings/authentication/saml-sso/ping-identity.md): Learn how to configure Ping Identity as an identity provider for NocoDB.
