SSO is an organisation-level setting that applies to everyone on your email domain. Setting it up is a joint effort between your IT team and Adclear support.
Before you start
Make sure you have:- Administrative access to the Microsoft Azure portal
- Permission to create and configure enterprise applications
- Permission to assign users to an enterprise application
- The email domain, or domains, your team signs in with (for example
@company.com)
Set up the app in Entra ID
1
Create the enterprise application
In the Azure portal, go to Enterprise applications and select New application. On the Browse Microsoft Entra Gallery page, select Create your own application.Give the app a name your team will recognise, such as “Adclear”, choose Integrate any other application you don’t find in the gallery (Non-gallery), then select Create.
2
Assign users or groups
Open Assign users and groups, then select Add user/group. Choose the people or groups who should be able to sign in to Adclear, then select Assign.
For advanced group assignment, see Microsoft’s documentation.
3
Enter the SAML settings
Under Manage, select Single sign-on, then choose SAML. In the Basic SAML Configuration section, select Edit and enter the values Adclear support gave you:
- Identifier (Entity ID): the value provided by Adclear
- Reply URL (Assertion Consumer Service URL): the value provided by Adclear
4
Check the attributes and claims
In the Attributes & Claims section, select Edit and confirm the email claim is present. Entra ID usually configures these by default, but it’s worth checking to avoid sign-in errors.
The email claim is required. Name claims are optional. If your organisation uses custom attribute names, update the Value column with your own attribute paths.
5
Copy the federation metadata URL
In the SAML Certificates section, copy the App Federation Metadata URL. You’ll send this to Adclear support in the next section.
What Adclear needs from you
To finish the connection, send Adclear support:- The App Federation Metadata URL you copied from the SAML Certificates section
- The email domain, or domains, this SSO applies to (for example
@company.com). Tell us whether to include subdomains such as@team.company.com.
What happens next
Once you’ve sent those details, Adclear support:- Configures the SSO connection on our side
- Tests it to confirm sign-in works end to end
- Confirms with you when it’s live
Troubleshooting
Users can't sign in
Users can't sign in
Check that each person is assigned to the enterprise application in Entra ID.
Sign-in fails with an attribute error
Sign-in fails with an attribute error
Confirm the attribute mappings, especially the email address claim.
Sign-in fails with a configuration error
Sign-in fails with a configuration error
Confirm the Identifier and Reply URL from Adclear were entered exactly as provided.
Related pages
Set up SSO with Okta
Use Okta as your identity provider instead.
How roles work
Understand what each role can do once your team signs in.