SAML with Microsoft Entra ID
Before you configure Entra, create your organization’s SAML connection in Kindo under Settings → SSO. You must be an organization Admin. Follow Single Sign-On (SSO) Setup and keep the ACS URL and SP Entity ID available.
Create or update the Entra application
Section titled “Create or update the Entra application”For an existing Kindo application, open it and continue with the SAML configuration below.
To create an application:
-
In Entra, open Applications → Enterprise applications.
-
Select New application → Create your own application.
-
Enter an application name. Continue creating your custom application when gallery suggestions appear.
-
Select Integrate any other application you don’t find in the gallery (Non-gallery). Select Create.
Configure SAML for the application:
-
Open Single sign-on and select SAML.
-
In Basic SAML Configuration, select Edit. Enter these values:
Entra field Value Identifier (Entity ID) Kindo SP Entity ID Reply URL (Assertion Consumer Service URL) Kindo ACS URL Sign-on URL Leave blank -
Select Save.
-
In Attributes & Claims, select Edit. Set Unique User Identifier (Name ID) to the attribute holding the user’s Kindo email address, typically
user.mail. Entra defaults to the user principal name (UPN), which can differ from the Kindo email address. -
Add these exact claim names. Leave the namespace blank.
Name Source attribute emailuser.mailgivenNameuser.givennamesurnameuser.surnameIf you chose another source for Name ID, use that same email source for the
emailclaim. -
Save the claims. Confirm that
emailand Name ID contain the same address on your organization’s verified domain.
The recommended givenName and surname claims populate the user’s display name. For claim options, see Customize SAML token claims.
Add Entra details in Kindo
Section titled “Add Entra details in Kindo”Use metadata XML to import the IdP settings:
-
On the application’s SAML configuration page in Entra, download Federation Metadata XML.
-
In Kindo, open Settings → SSO → Identity Provider (IdP) Configuration.
-
Select Upload metadata XML and choose the downloaded file. The file imports immediately. To paste the metadata, copy the downloaded XML contents into Kindo and select Import.
-
Confirm that the certificate shows
Valid until <date>.
For manual configuration:
-
Enter these values in Identity Provider (IdP) Configuration:
Kindo field Entra value IdP Entity ID Microsoft Entra Identifier Redirect URL Login URL Signing certificate Full PEM contents of the Certificate (Base64) download -
Select Save. Confirm that the certificate shows
Valid until <date>.
Assign users and test
Section titled “Assign users and test”Users must be assigned to the Entra application to sign in.
-
In Entra, open Users and groups and assign a pilot user or group.
-
Open Kindo in a private browser window. Select Continue with SAML SSO and enter the pilot user’s email address. Complete sign-in with Entra.
-
Test sign-in from the Kindo tile in My Apps.
-
Assign the remaining users or groups after the pilot succeeds.
-
If your organization requires SSO, enable SSO Enforcement. Test a fresh sign-in with enforcement enabled.
