> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.simplyprint.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Setting up SAML Single Sign-On (SSO) with Microsoft Entra ID for SimplyPrint

| This guide is for SimplyPrint customers with the Print Farm, School or Enterprise plan who use Google Workspace as their Identity Provider for Single Sign-On.
| If you don't use Google Workspace, but rather another SSO provider, check out our other SSO guide(s) here: [Set up Single sign-on (SSO) for SimplyPrint](https://help.simplyprint.io/en/article/set-up-single-sign-on-sso-for-simplyprint-4coj1g/)

This guide explains how to connect **Microsoft Entra ID (formerly Azure AD)** with **SimplyPrint** using SAML 2.0. After setup, staff and students can log in to SimplyPrint using their Microsoft 365 accounts.

You can follow the interactive guide below, or the written instructions further down to see exactly how to set up SimplyPrint SSO with Microsoft Entra.

${frame}[Demo](https://demo.arcade.software/r50MawY9SQj8ZrnpLElP?embed&embed_mobile=tab&embed_desktop=inline&show_copy_link=false)
| Tip: if you or anyone from your team already has a SimplyPrint account, created without SSO, you can link your account after setting up SSO! More here: [Linking your existing SimplyPrint account to your SSO account](https://help.simplyprint.io/en/article/linking-your-existing-simplyprint-account-to-your-sso-account-5pw0aj/)

## Part 1: Prepare SimplyPrint
1. Go to your SimplyPrint dashboard → [Organization Settings → Registration & SSO](https://simplyprint.io/panel/settings/organization#registration).
2. Enable **SAML Single Sign-On (SSO)**.
3. Click **Edit SAML Configuration**.

Keep this tab open — you’ll come back to paste Microsoft details into it.

## Part 2: Create a new enterprise application in Microsoft Entra

| More info on how to add an Enterprise Application in Entra can be found in the Microsoft Entra Learning space: https://learn.microsoft.com/en-us/entra/architecture/auth-saml and https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/add-application-portal

1. Open the [Microsoft 365 Admin Center](https://admin.microsoft.com/#/homepage) and click **Identity**, or go directly to [Microsoft Entra Admin Center](https://entra.microsoft.com/).
2. Go to **Identity → Applications → Enterprise applications**.
3. Click **+ New application**.
4. Choose **Create your own application**.
5. Enter a name (e.g. **SimplyPrint**) and click **Create**.

## Part 3: Assign users and groups
1. In the new application, go to **Users and groups**.
2. Decide which users (or groups) should be allowed to access SimplyPrint.
    * Example: assign “All Students” and “All Teachers” groups.

## Part 4: Configure SAML SSO in Entra
1. In the new application, go to **Single sign-on**.
2. Choose **SAML** as the sign-on method.
3. Under **Basic SAML Configuration**, click **Edit**.
4. Enter the following values (found in your SimplyPrint metadata file):
    * **Identifier (Entity ID)** → Copy from SimplyPrint metadata.
    * **Reply URL (ACS URL)** → Copy from SimplyPrint metadata.
5. Click **Save**.

## Part 5: Download and copy the IdP certificate
1. In the Entra **Single sign-on** setup page, go to **SAML Certificates (Step 3)**.
2. Download the **Base64 certificate**.
3. Open it in a text editor and copy the full content (including `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----`).

## Part 6: Enter Microsoft Entra details in SimplyPrint
Back in **SimplyPrint → Edit SAML Configuration**, fill in:
* **Entity ID** – Found in Entra → Single sign-on → **Identifier**.
* **SSO URL (Login URL)** – Found in Entra → Single sign-on → **Login URL**.
* **X.509 Certificate** – Paste the Base64 certificate content.
* **SSO Binding** – Leave as **HTTP-Redirect** (default).
Click **Save**.

## Part 7: Configure attribute mappings
In Microsoft Entra, under **Attributes & Claims**, map user data to SimplyPrint.
### Required
| SimplyPrint field | Typical Microsoft attribute | Notes |
| ---- |
| `first_name` | `givenname` | Required |
| `last_name` | `surname` | Required |
| `email` | `emailaddress`, `userprincipalname` or `mail` | Optional |
### Optional
| SimplyPrint field | Typical Microsoft attribute | Notes |
| ---- |
| `user_group` | `groups` | Optional. Requires group claim setup |
| `school_is_teacher` | Custom claim (true/false) | Optional. For schools |
| `school_classes` | Custom claim or `memberOf` | Optional. For schools |
👉 Attribute names in Entra often look like schema URLs, e.g.:
* `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname`
* `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname`
Both are valid — just match what you configure in SimplyPrint.

## Part 8: Test the connection
1. In Microsoft Entra → **Single sign-on**, click **Test**.
2. Sign in with a user you assigned earlier.
3. If login fails, check:
    * Identifier and Reply URL match SimplyPrint’s metadata.
    * Certificate is copied correctly.
    * Attribute mappings are set and match SimplyPrint’s fields.

## Part 9: (Optional) Show your school on the SimplyPrint login page
To make login easier for students:
1. In [Organization Settings → Registration & SSO](https://simplyprint.io/panel/settings/organization#registration), enable:
**“Show school/organization in the public list shown on login page.”**
2. Your school will now appear in the dropdown at:
    * [https://simplyprint.io/panel/login](https://simplyprint.io/panel/login)
    * [https://simplyprint.io/panel/login/school](https://simplyprint.io/panel/login/school)

**See how to log in using SSO here**: [Signing in with SSO / Organization Login](https://help.simplyprint.io/en/article/signing-in-with-sso-organization-login-1v0eb2h/)

# Link existing accounts (email & password signups) to an SSO account
If you, members of your team or students have already signed up for your SimplyPrint organization without SSO, by simply registering on our site with their name, email and password, they can

**Learn how to here:** [Linking your existing SimplyPrint account to your SSO account](https://help.simplyprint.io/en/article/linking-your-existing-simplyprint-account-to-your-sso-account-5pw0aj/)

# Issues? Troubleshoot your SSO integration here!
Visit our "SSO troubleshooting" guide for troubleshooting help: [SSO troubleshooting: how to fix errors like "first_name not set"](https://help.simplyprint.io/en/article/sso-troubleshooting-how-to-fix-errors-like-firstname-not-set-pgdbiz/)
