> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-feat-poc-api-playground.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML: Entra ID Configuration

> This document provides instructions for creating an application within Entra ID for compatibility with BloodHound Enterprise.

<img noZoom src="https://mintcdn.com/specterops-feat-poc-api-playground/5XJ7p5p7xL9ZwxE2/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=5XJ7p5p7xL9ZwxE2&q=85&s=79b8dea14cb2266671c0a2f64f4b9caa" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

For general instructions on adding a SAML provider to BloodHound Enterprise or for configuring users to utilize a SAML provider, see [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml).

See [SAML Order of Operations and Quick Reference](/manage-bloodhound/auth/saml) before starting.

## Create an Enterprise Application

1. Login to Azure at [https://portal.azure.com](https://portal.azure.com)
2. Navigate to the **Enterprise Applications** section of Entra ID.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-44.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=ebcae1a2dea6d50fc7c4d35347c02d24" width="430" height="207" data-path="assets/image-2-44.png" />
</Frame>

3. Click **New Application**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-46.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=c3a0128a2e908009f9fdb9731aedb20b" width="564" height="171" data-path="assets/image-2-46.png" />
</Frame>

4. Click **Create your own application**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-47.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=24c11e05383544cbfb3d04ed59e2fdc5" width="484" height="231" data-path="assets/image-2-47.png" />
</Frame>

5. Provide a name for your application and click **Create**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-48.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=72805f75b5de3186a9d53360e3624cf3" width="573" height="850" data-path="assets/image-2-48.png" />
</Frame>

## Configure Single Sign-On Settings

1. Your browser should redirect you to your newly created application. Click on **Single sign-on**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-49.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=7ececc7b5d54c7c0a241fa0e87d229a4" width="406" height="498" data-path="assets/image-2-49.png" />
</Frame>

2. Click on **SAML**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-50.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=2884948e2cc84d22727ccbeb729263dd" width="370" height="199" data-path="assets/image-2-50.png" />
</Frame>

3. Click **Edit** under the Basic SAML Configuration section.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-51.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=429267dbe069d37e847cb6382dc9d835" width="760" height="226" data-path="assets/image-2-51.png" />
</Frame>

4. Configure SAML. The following screenshot shows the tenant codename is "demo" and the provider name is "entra".

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-52.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=837a17d41abc6e3db07818da9dafbec5" width="793" height="651" data-path="assets/image-2-52.png" />
</Frame>

5. Azure will inform you the settings have saved successfully.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-53.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=126826262e02e3faf85c6cc31c6786f3" width="358" height="77" data-path="assets/image-2-53.png" />
</Frame>

6. Click the **X** to close the dialog.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-54.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=4ba7081312695ee24c3bf77bc4a85a99" width="859" height="250" data-path="assets/image-2-54.png" />
</Frame>

7. Scroll down to the **SAML Certificates** section and download the **Metadata XML**.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-55.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=0e20af0135e2a1d99b14f43bae5504b4" width="765" height="408" data-path="assets/image-2-55.png" />
</Frame>

8. Use the **Users and Groups** section to configure groups and users which you would like to grant access to BloodHound Enterprise.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-56.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=e584546eb5d1f3b1db0402c2696ab071" width="436" height="371" data-path="assets/image-2-56.png" />
</Frame>

9. Use the downloaded metadata.xml file and follow the instructions at [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml) to Create the SAML Configuration in BloodHound.

## Troubleshooting

Verify your attributes and claims use a proper schema in the claim name, and that you have a properly mapped claim for "user.mail" as in the example below. An indicator that this is necessary is when an authentication attempt returns the response: "*assertion does not meet requirements for user lookup*".

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-57.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=9564287e834791cd27c809de8df6e8a8" width="1075" height="988" data-path="assets/image-2-57.png" />
</Frame>
