Microsoft Entra ID SSO setup (original) (raw)

  1. All Collections
  2. Identity management (SSO, JIT, SCIM)
  3. Setup by identity provider
  4. Microsoft Entra ID SSO setup

This guide walks you through configuring single sign-on (SSO) for Claude using Microsoft Entra ID (formerly Azure Active Directory) as your identity provider. It applies to Team plans, Enterprise plans, and Console organizations.

Prerequisites

Where to find your configuration values

The Entity ID, Reply URL (ACS URL), and SCIM credentials referenced below are provided in the WorkOS setup flow within your Identity and access settings — not by contacting Support.

Start the SSO setup flow there and keep it open alongside the Entra Admin Center as you work through the steps below.

Step 1 — Add Claude as an enterprise application in Entra

Step 2 — Configure SAML SSO

Step 3 — Configure SCIM provisioning

Critical: The attribute used for SCIM email and SSO email must be identical. Mismatches are the most common cause of login failures. For troubleshooting, see Microsoft Entra ID SSO/SCIM email mismatch.

Step 4 — Assign people and groups

Step 5 — Verify

Need help?

See Set up single sign-on for the full end-to-end flow including domain verification and choosing a provisioning approach. If you run into issues, contact our Support team with your Entra tenant ID and a screenshot of your SAML configuration.


Related Articles

Microsoft Entra ID SSO/SCIM email mismatchGoogle Workspace SSO setupOkta SSO setupOneLogin SSO setupPing Identity SSO setup