Skip to content

SAML with Microsoft Entra ID

Before you configure Entra, create your organization’s SAML connection in Kindo under Settings → SSO. You must be an organization Admin. Follow Single Sign-On (SSO) Setup and keep the ACS URL and SP Entity ID available.

For an existing Kindo application, open it and continue with the SAML configuration below.

To create an application:

  1. In Entra, open Applications → Enterprise applications.

  2. Select New application → Create your own application.

  3. Enter an application name. Continue creating your custom application when gallery suggestions appear.

  4. Select Integrate any other application you don’t find in the gallery (Non-gallery). Select Create.

Configure SAML for the application:

  1. Open Single sign-on and select SAML.

  2. In Basic SAML Configuration, select Edit. Enter these values:

    Entra fieldValue
    Identifier (Entity ID)Kindo SP Entity ID
    Reply URL (Assertion Consumer Service URL)Kindo ACS URL
    Sign-on URLLeave blank
  3. Select Save.

  4. In Attributes & Claims, select Edit. Set Unique User Identifier (Name ID) to the attribute holding the user’s Kindo email address, typically user.mail. Entra defaults to the user principal name (UPN), which can differ from the Kindo email address.

  5. Add these exact claim names. Leave the namespace blank.

    NameSource attribute
    emailuser.mail
    givenNameuser.givenname
    surnameuser.surname

    If you chose another source for Name ID, use that same email source for the email claim.

  6. Save the claims. Confirm that email and Name ID contain the same address on your organization’s verified domain.

The recommended givenName and surname claims populate the user’s display name. For claim options, see Customize SAML token claims.

Use metadata XML to import the IdP settings:

  1. On the application’s SAML configuration page in Entra, download Federation Metadata XML.

  2. In Kindo, open Settings → SSO → Identity Provider (IdP) Configuration.

  3. Select Upload metadata XML and choose the downloaded file. The file imports immediately. To paste the metadata, copy the downloaded XML contents into Kindo and select Import.

  4. Confirm that the certificate shows Valid until <date>.

For manual configuration:

  1. Enter these values in Identity Provider (IdP) Configuration:

    Kindo fieldEntra value
    IdP Entity IDMicrosoft Entra Identifier
    Redirect URLLogin URL
    Signing certificateFull PEM contents of the Certificate (Base64) download
  2. Select Save. Confirm that the certificate shows Valid until <date>.

Users must be assigned to the Entra application to sign in.

  1. In Entra, open Users and groups and assign a pilot user or group.

  2. Open Kindo in a private browser window. Select Continue with SAML SSO and enter the pilot user’s email address. Complete sign-in with Entra.

  3. Test sign-in from the Kindo tile in My Apps.

  4. Assign the remaining users or groups after the pilot succeeds.

  5. If your organization requires SSO, enable SSO Enforcement. Test a fresh sign-in with enforcement enabled.