# Azure AD Saml SSO not working - Invalid login. Please verify credentials

**URL:** <https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440>\
**Category:** Product Support\
**Tags:** mautic-4\
**Created:** [June 26, 2023, 9:41pm UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440 "2023-06-26T21:41:32Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![jasjitchopra](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@jasjitchopra](https://forum.mautic.org/u/jasjitchopra)\
**Post date:** [June 30, 2023, 12:38pm UTC](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440/3 "2023-06-30T12:38:49Z")

</div>

I got this working using advice from here: [Microsoft SSO Integration - Solved](https://forum.mautic.org/t/microsoft-sso-integration-solved/21141)

So you have to use complete url for attributes as defined in the schema of the metadata xml.

For email I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)  
For Frist Name I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname)  
For Last Name I used this: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname)  
And since I tend to configure usernames as email (personal choice) I used this fro Username which is optional: [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)

You define these settings in the Mautic SAML SSO Settings page

---

_[View the full topic](https://forum.mautic.org/t/azure-ad-saml-sso-not-working-invalid-login-please-verify-credentials/28440)._
