Skip to main content

How do I set up SSO with Microsoft Entra ID?

Learn how to connect Microsoft Entra ID to Marvia with Single Sign-On (SSO).

Written by Maarten Peters

This guide is for Entra ID administrators. Replace {your-portal-domain} with your Marvia portal host, for example acme.getmarvia.com. Marvia connects to Microsoft Entra ID using SAML 2.0. OpenID Connect is not used for this integration.

Create an Enterprise Application in Microsoft Entra ID, then send Marvia the values listed at the end of this page. After we save them, users can sign in with the SSO button on your Marvia login page.


​

1. Create the Enterprise Application

  1. In the Microsoft Entra admin center (entra.microsoft.com), navigate to Identity → Applications → Enterprise applications.

  2. Click + New application, then select + Create your own application.

  3. Enter a name for your app, for example Marvia.

  4. Select Integrate any other application you don't find in the gallery (Non-gallery) and click Create.

2. Configure SAML Settings

  1. In your new application's menu, select Single sign-on and select SAML.

  2. In section 1. Basic SAML Configuration, click Edit and enter these values:

Entra ID field

Value

Identifier (Entity ID)

https://{your-portal-domain}/saml/metadata (Set as Default)

Reply URL (Assertion Consumer Service URL)

https://{your-portal-domain}/saml/acs

Sign on URL

https://{your-portal-domain}/login

(Optional) You can also click Upload metadata file at the top of the section and import Marvia's metadata from: https://{your-portal-domain}/saml/metadata


​

3. Attributes & Claims

In section 2. Attributes & Claims, click Edit. Marvia expects standard claims mapped to user profile properties.


​

User Claims

Ensure the following claim mappings are configured (edit existing default claims or add missing ones):

Claim name

Value / Source attribute

firstName

user.givenname

lastName

user.surname

email

user.mail (or user.userprincipalname)

Note: Ensure the Namespace field is left blank for these claims so the sent claim name is exact.

Groups (optional)

If users should be placed in Marvia groups automatically:

  1. Click + Add a group claim.

  2. Choose Security groups (or Directory roles / All groups as needed by your organization).

  3. Set the Source attribute to Group ID (or Group display name depending on your Marvia setup).

  4. Set the Claim name to groups.

Locations (optional)

If you use location or branch access in Marvia, add a claim named locations:

Claim name

Value / Source attribute

locations

The Entra ID user profile attribute that holds the location or office name (e.g., user.physicaldeliveryofficename or a custom extension attribute)

4. Assign Users and Groups

  1. Under the app menu, select Users and groups.

  2. Click + Add user/group and select the users or groups that should be granted access to sign in to Marvia.

5. Send these values to Marvia

In section 3. SAML Certificates and section 4. Set up Marvia, copy the following values and send them to your Marvia support representative:
​

  • Microsoft Entra Identifier (Entity ID)

  • Login URL (Identity Provider Single Sign-On URL)

  • Certificate (Base64): Download the Certificate (Base64) file, open it in a text editor, and copy the full text including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines.

  • Logout URL (Optional, if you use single logout)

Once we have saved these on our side, users can sign in with the SSO button on your Marvia login page.

Did this answer your question?