Azure Single Sign-On (SSO) with a Third-Party Application — SAML Authentication Setup
This implementation service configures single sign-on between Microsoft Entra ID and a third-party application that supports SAML authentication, so selected users sign in to that service with their Entra ID credentials. IT Partner creates and configures the Enterprise application — from the Microsoft Entra ID application gallery or as a non-gallery custom SAML registration — configures the third-party service, and enables and tests SSO. The service is $350, runs 2 days, and is managed by Roman Sotnik.
What this engagement is
Single sign-on (SSO) means users do not need to sign in to every application they use with separate credentials. A user logs into Microsoft Entra ID once, and those credentials authenticate them to other applications — services such as Salesforce, Slack, Zendesk, and many others. In Entra ID this is implemented through an Enterprise application: either a pre-integrated entry from the Microsoft Entra ID application gallery or, for applications not in the gallery, a non-gallery custom SAML app registration. SSO-based authentication is part of modern authentication, and it falls into the identity and access management (IAM) discipline: one identity, centrally controlled, with sign-in policies applied in one place.
Success criteria
What you receive
How the work unfolds
Confirm the target third-party application, business owner, test users, preferred implementation window, required administrator access, and communication approach for affected users.
Gather the application's SAML SSO requirements, including entity ID, reply URL/ACS URL, sign-on URL, certificate requirements, user identifier format, required claims or attributes, and any vendor-specific setup instructions.
Access the client Microsoft 365/Azure tenant with approved administrative permissions and review the Microsoft Entra ID configuration needed to create or configure the Enterprise application.
Access the third-party application administration portal with approved permissions and locate the SAML/SSO configuration area required for the integration.
Create and configure the Entra ID Enterprise application — from the application gallery or as a non-gallery custom SAML registration — exchange SAML metadata or configuration values between Entra ID and the third-party service, configure required claims and certificate settings, and assign the selected users or groups.
Test the SSO sign-in flow with selected users, validate successful authentication to the third-party service using Entra ID credentials, troubleshoot configuration issues, and confirm readiness for project closeout.
Prerequisites
Who does what
IT Partner
- Check prerequisites for SSO implementation
- Create an Enterprise application for the required service
- Configure this application according to the requirements
- Configure the required third-party service
- SSO enabling and testing
Your team
- Coordinate Client resources and staff schedules
- Provide a dedicated point of contact responsible for working with IT Partner
- Coordinate any outside vendor resources and schedules
- Provide administrative access to Microsoft 365 tenant
- Notify users about new services
- Review and approve engagement deliverables in a timely manner
What's not included
Limitations & technical notes
Frequently asked questions
What does the Azure Single Sign-On (SSO) with a Third-Party Application service include?
IT Partner configures single sign-on between Microsoft Entra ID and a third-party application that supports SAML: prerequisite checks, creation and configuration of the Enterprise application in your tenant, configuration of the third-party service, SSO enablement, sign-in testing with selected users, and a project closeout report.
How much does the SSO implementation cost, and how long does it take?
The service is $350 and runs 2 days, quoted fixed-price in writing before work begins.
Which third-party applications can be connected with this service?
Applications that support SAML authentication. Many are pre-integrated in the Microsoft Entra ID application gallery — services such as Salesforce, Slack, and Zendesk — and applications not in the gallery can be connected as a non-gallery custom SAML registration. The specific application is reviewed for compatibility before implementation.
What are the prerequisites for this Azure SSO service?
Administrative access to your company tenant, administrative access to the third-party service you want to connect, and SAML support in that service. Both sides of access are needed because IT Partner configures the Entra ID Enterprise application and the third-party application's SSO settings.
Does this service use Microsoft Entra ID credentials for login?
Yes. The purpose of the service is that selected users authenticate to the third-party service with their Entra ID credentials — one identity, controlled centrally in your tenant, instead of separate credentials for that application.
Is this service for SAML-based SSO only?
Yes, the stated prerequisite is that the third-party service supports SAML authentication. If the application uses a different authentication method — such as OpenID Connect only — or has special integration requirements, the scope is confirmed with IT Partner before purchase.
How are users selected for SSO access?
IT Partner assigns the agreed users or groups to the Enterprise application during configuration, and those selected users validate the sign-in flow during testing. User selection and rollout timing are confirmed during data collection, because they depend on the application and tenant requirements.
What happens during the engagement?
A kickoff confirms the application and stakeholders; IT Partner collects the application's SAML requirements — entity ID, reply URL, certificate and claims requirements — connects to your tenant and the third-party admin portal, configures both sides of the SSO integration, assigns users, and verifies the sign-in flow before closeout.
Will users experience downtime during SSO configuration?
Enabling SSO changes how users sign in to the third-party application, so timing and user notification are coordinated with your point of contact before the change. The engagement includes testing with selected users before the new sign-in experience is relied on broadly.
Does this service include user provisioning, conditional access, or MFA rollout?
No. Automatic user provisioning (SCIM), conditional access policy design, and multifactor authentication rollout are not part of this fixed-scope implementation; they can be scoped separately. This engagement delivers working SAML SSO for the selected application and users.
Will this service migrate our application data to Azure?
No. Migration of data to Azure — applications, mail, virtual machines, databases, or files — is not included and can be purchased as an additional service. Workstation configuration is also outside the scope.
What do we receive at the end of the project?
A working SSO integration — the configured Enterprise application, the configured third-party service, and validated sign-in for selected users — plus a project closeout report with final status, acceptance criteria matching, outstanding issues if any, and the final budget. More extensive documentation is available for an additional fee.