Skip to main content
Single sign-on (SSO) lets your team sign in to Adclear through Microsoft Entra ID (formerly Azure Active Directory), using the accounts and access policies you already manage there. Adclear supports Entra ID through SAML.
SSO is an organisation-level setting that applies to everyone on your email domain. Setting it up is a joint effort between your IT team and Adclear support.

Before you start

Make sure you have:
  • Administrative access to the Microsoft Azure portal
  • Permission to create and configure enterprise applications
  • Permission to assign users to an enterprise application
  • The email domain, or domains, your team signs in with (for example @company.com)
You’ll also need a set of connection values (an Identifier and a Reply URL) that are unique to your organisation. Contact Adclear support to generate them before you begin. You’ll enter them in Entra ID during setup.

Set up the app in Entra ID

Adclear support provides the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) in the steps below. Ask our team for these values for your organisation before you start.
1

Create the enterprise application

In the Azure portal, go to Enterprise applications and select New application. On the Browse Microsoft Entra Gallery page, select Create your own application.Give the app a name your team will recognise, such as “Adclear”, choose Integrate any other application you don’t find in the gallery (Non-gallery), then select Create.
2

Assign users or groups

Open Assign users and groups, then select Add user/group. Choose the people or groups who should be able to sign in to Adclear, then select Assign.
For advanced group assignment, see Microsoft’s documentation.
3

Enter the SAML settings

Under Manage, select Single sign-on, then choose SAML. In the Basic SAML Configuration section, select Edit and enter the values Adclear support gave you:
  • Identifier (Entity ID): the value provided by Adclear
  • Reply URL (Assertion Consumer Service URL): the value provided by Adclear
Select Save and close the panel.
4

Check the attributes and claims

In the Attributes & Claims section, select Edit and confirm the email claim is present. Entra ID usually configures these by default, but it’s worth checking to avoid sign-in errors.
The email claim is required. Name claims are optional. If your organisation uses custom attribute names, update the Value column with your own attribute paths.
5

Copy the federation metadata URL

In the SAML Certificates section, copy the App Federation Metadata URL. You’ll send this to Adclear support in the next section.

What Adclear needs from you

To finish the connection, send Adclear support:
  1. The App Federation Metadata URL you copied from the SAML Certificates section
  2. The email domain, or domains, this SSO applies to (for example @company.com). Tell us whether to include subdomains such as @team.company.com.

What happens next

Once you’ve sent those details, Adclear support:
  1. Configures the SSO connection on our side
  2. Tests it to confirm sign-in works end to end
  3. Confirms with you when it’s live
Your team can then sign in to Adclear with their Microsoft credentials.
If existing users have email addresses on the SSO domain, they’ll need to sign in through Entra ID once SSO is enabled. If that applies to your team, we recommend switching it on during off-peak hours.

Troubleshooting

Check that each person is assigned to the enterprise application in Entra ID.
Confirm the attribute mappings, especially the email address claim.
Confirm the Identifier and Reply URL from Adclear were entered exactly as provided.
For anything else, contact Adclear support with details of the error you’re seeing.

Set up SSO with Okta

Use Okta as your identity provider instead.

How roles work

Understand what each role can do once your team signs in.