# Configuring Mautic Single Sign-On with SAML with Azure AD as the Identity Provider

**URL:** <https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843>\
**Category:** Product Support\
**Tags:** mautic-4\
**Created:** [January 24, 2023, 3:40pm UTC](https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843 "2023-01-24T15:40:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![chansey](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/chansey/32/9176_2.png) [@chansey](https://forum.mautic.org/u/chansey)\
**Post date:** [January 24, 2023, 3:40pm UTC](https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843/1 "2023-01-24T15:40:49Z")

</div>

**Your software**  
My Mautic version is: v4.4.5  
My PHP version is: 7.4.33  
My Database type and version is: 10.2.32-MariaDB-log

**Your problem**  
My problem is:  
Currently setting up Mautic’s Single Sign-On with SAML with Azure AD as the Identity provider.  
I have provided the required SAML SSO settings on the Mautic portal as well as the required setting on the side of Azure Enterprise Application Single Sign on setting.

So upon accessing the Mautic’s URL, i get redirected to the Microsoft login then i was able to login using my Azure AD credentials. After that I get redirected back to the Mautic Login portal with this error prompt  
 ![image](https://us1.discourse-cdn.com/flex020/uploads/mautic/original/2X/0/0afbb25be0627972ee93d48aa949043d1c8709a8.png)

These errors are showing in the log:  
Invalid inbound message destination “[https://your-mautic.com/s/saml/login\_check](https://your-mautic.com/s/saml/login_check)”

Steps I have tried to fix the problem:  
I tried different values for the Assertion consumer service setting on the Azure side.  
As per Mautic documentation ([Authentication | Mautic](https://docs.mautic.org/en/authentication)), the value of the Assertion consumer service should be [https://your-mautic.com/s/saml/login\_check](https://your-mautic.com/s/saml/login_check).  
However, the path provided cant be found upon direct access.

---

<div class="post-metadata">

**Author:** ![peterk](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/peterk/32/511_2.png) [@peterk](https://forum.mautic.org/u/peterk)\
**Post date:** [April 21, 2023, 8:12am UTC](https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843/2 "2023-04-21T08:12:48Z")

</div>

Were you able get this working yet? I’m also struggling in a similar way currently and the documentation is quite sparse on how to do this.

---

<div class="post-metadata">

**Author:** ![ferrao](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/ferrao/32/10456_2.png) [@ferrao](https://forum.mautic.org/u/ferrao)\
**Post date:** [September 5, 2023, 4:11pm UTC](https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843/3 "2023-09-05T16:11:06Z")

</div>

Is anyone able to figure this out? Now AzureAD is named Entra, but it’s still the same issue.

---

<div class="post-metadata">

**Author:** ![gem](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mautic.org/gem/32/12648_2.png) [@gem](https://forum.mautic.org/u/gem)\
**Post date:** [December 3, 2024, 4:50pm UTC](https://forum.mautic.org/t/configuring-mautic-single-sign-on-with-saml-with-azure-ad-as-the-identity-provider/26843/4 "2024-12-03T16:50:41Z")

</div>

I chased this same issue for two days now, and have found a workaround if you are using Cloudflare or a reverse proxy in front of Mautic. The flow only breaks if Mautic initiates the SAML flow. If you start the login flow from the IdP, then it logs in fine. I set up a redirect in my reverse proxy (Traefik in my case) to intercept any requests to [https://myweburl.com/saml/discovery](https://myweburl.com/saml/discovery) and 302 redirect them to the login URL provided by my IdP (Entra), similar to this:

> h ttps://launcher.myapps.microsoft.com/api/signin/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx?tenantId=yyyyyyyy-yyyy-yyyy-yyyy-yyyyyyyyyyyy

This drops the SAML flow initiated by Mautic when navigating to the root URL, and starts a new one initiated by the IdP.
