> For the complete documentation index, see [llms.txt](https://docs.cybaops.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cybaops.com/settings/advanced-security-settings-overview/setting-up-single-sign-on-sso.md).

# Setting Up Single Sign On (SSO)

### <mark style="color:$primary;">CybaOps SSO Setup Guide (Microsoft / Azure AD)</mark>&#x20;

This guide explains how to configure SAML 2.0 Single Sign-On (SSO) in CybaOps using Microsoft Entra ID (formerly Azure AD).&#x20;

#### <mark style="color:$primary;">**Overview of What You’ll Do**</mark>&#x20;

1. Create an Enterprise Application in Microsoft Entra ID &#x20;
2. Configure SAML settings in Microsoft &#x20;
3. Copy required values into CybaOps &#x20;
4. Upload certificate and test login &#x20;

### <mark style="color:$primary;">**Step 1: Create an Enterprise Application**</mark>&#x20;

1. Go to: Microsoft Entra Admin Center &#x20;
2. Navigate to: \
   Applications → Enterprise Applications → New Application &#x20;
3. Click Create your own application &#x20;
4. Name it (e.g., CybaOps Platform Admin SSO) &#x20;
5. Select: \
   “Integrate any other application you don’t find in the gallery” &#x20;

### <mark style="color:$primary;">**Step 2: Configure SAML SSO in Microsoft**</mark>&#x20;

1. Open your new app &#x20;
2. Go to: Single sign-on &#x20;
3. Choose: SAML &#x20;
4. Edit Basic SAML Configuration&#x20;
5. This can be found in the Setup Single Sign-On drawer under “Issuer Callback URL”. Copy from CybaOps to Entra into “Identifier” and "Reply URL”. &#x20;
6. Download the Certificate (Base64) file, you will need to copy and paste this into CybaOps.&#x20;

<figure><img src="/files/ztTrr1du37GcFbL7uoTt" alt=""><figcaption></figcaption></figure>

### <mark style="color:$primary;">**Step 3: Map Microsoft Fields to CybaOps Fields**</mark>&#x20;

Below is where you can find each required field in Microsoft and CybaOps.&#x20;

1\. Name&#x20;

* This is created by you as an identifier for the SSO &#x20;
* Example: CybaOps Platform Admin SSO &#x20;

2\. Certificate&#x20;

Enter the information from the certificate downloaded from Entra; it will look something like this: &#x20;

\-----BEGIN CERTIFICATE----- MIIDXTCCAkWgAwIBAgIJAO3x9k2uQ9zDMA0GCSqGSIb3DQEBCwUAMEUxCzAJBgNV BAYTAkdCMRMwEQYDVQQIDApxdWFzaS1sYW5kMRMwEQYDVQQKDApFeGFtcGxlIElu YzAeFw0yNDAxMDEwMDAwMDBaFw0yNTAxMDEwMDAwMDBaMEUxCzAJBgNVBAYTAkdC MRMwEQYDVQQIDApxdWFzaS1sYW5kMRMwEQYDVQQKDApFeGFtcGxlIEluYzCCASIw DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALt8z0q3zv5u8x7oJqk9pZJ4uQ0p 3yJ8tq1Y8Y0x9V7o8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3 pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Q m3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u 8QIDAQABo1AwTjAdBgNVHQ4EFgQUuQ2pQ2x9x0l3pY8u8Qm3pJQb8x0wHwYDVR0j BBgwFoAUuQ2pQ2x9x0l3pY8u8Qm3pJQb8x0wDAYDVR0TBAUwAwEB/zANBgkqhkiG 9w0BAQsFAAOCAQEAj3z0s8k9uQ0p3yJ8tq1Y8Y0x9V7o8Qm3pJQb8x0YV9x0l3pY 8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3 pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0l3pY8u8Qm3pJQb8x0YV9x0 l3pY8u8Q== &#x20;

\-----END CERTIFICATE-----&#x20;

3\. Issuer Login URL (IdP Login URL) &#x20;

This is pre-populated for you – do not amend&#x20;

<figure><img src="/files/P1wZBkxCkAqK1qrOi4xd" alt=""><figcaption></figcaption></figure>

You can paste this into the “Sign on URL” section when editing “Basic SAML Configuration”.&#x20;

<figure><img src="/files/6uVEIFRCk6F3LgqFqAS5" alt=""><figcaption></figcaption></figure>

4\. Issuer Callback URL (Assertion Consumer Service URL)&#x20;

This is pre-populated for you – do not amend &#x20;

<figure><img src="/files/Ut5nbGhrw6YHbckcFPum" alt=""><figcaption></figcaption></figure>

This is the URL you will paste into the “Identifier” and “Reply URL” section of **Entra** when editing “Basic SAML Configuration”.&#x20;

<figure><img src="/files/R2MfARkfMxQYvUrplCBi" alt=""><figcaption></figcaption></figure>

5\. Provider Login URL (Service Provider URL). You will paste this Login URL from **Entra** to **CybaOps**, it is found in section 4 - “Set up ‘Name’”. &#x20;

<figure><img src="/files/mK9bq0dGgCTwXISL59f7" alt=""><figcaption></figcaption></figure>

It will appear in the format [https://login.microsoftonline.com/\<tenant-id>/saml2](https://login.microsoftonline.com/%3ctenant-id%3e/saml2), with the tenant ID automatically populated for your organisation.&#x20;

<figure><img src="/files/2FvuJYPvQRjIcCSTQ2oK" alt=""><figcaption></figcaption></figure>

7\. Token (Optional / Platform-Specific) - This is pre-populated for you – do not amend&#x20;

### 🔁 <mark style="color:$primary;">IDP-Initiated Login</mark>&#x20;

IDP = Identity Provider (Microsoft)&#x20;

There are two login flows:&#x20;

#### 1. SP-Initiated (Default – Recommended)&#x20;

* User goes to CybaOps &#x20;
* Clicks “Login with SSO” &#x20;
* Redirected to Microsoft &#x20;

✅ More secure \
✅ Better control \
✅ Standard modern approach&#x20;

#### 2. IDP-Initiated&#x20;

* User logs in from Microsoft My Apps portal &#x20;
* Clicks CybaOps app tile &#x20;
* Gets logged into CybaOps automatically &#x20;

🔘 **CybaOps Toggle: IDP-Initiated**&#x20;

<mark style="color:$success;">**ON → Enables:**</mark>&#x20;

* Login directly from Microsoft portal &#x20;
* App tile launch experience &#x20;

<mark style="color:red;">**OFF → Disables:**</mark>&#x20;

* Users must start login from CybaOps &#x20;

✅ **Final Checklist**&#x20;

Before going live:&#x20;

* Check myapps to see if Cybaverse in there&#x20;
* Certificate uploaded &#x20;
* Issuer Login URL correct &#x20;
* Callback URL matches exactly Identifier and Reply URL&#x20;
* Users assigned in Microsoft &#x20;
* Test login successful&#x20;

&#x20;


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cybaops.com/settings/advanced-security-settings-overview/setting-up-single-sign-on-sso.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
