Sign in with OneLogin through Microsoft Entra
On this page
Use the OneLogin SAML Custom Connector (Advanced) to authenticate users upstream of Entra. Begin with the shared prerequisites and SAML values.
Configure OneLogin
- Add SAML Custom Connector (Advanced) in the administrator portal.
- Under Configuration, set Audience (EntityID) to the shared audience. Set Recipient and ACS (Consumer) URL to the shared ACS.
- Set ACS (Consumer) URL Validator to the exact anchored expression below.
- Set SAML initiator to Service Provider and SAML nameID format to Persistent. Select assertion signing.
- Under Parameters, add the shared email claim, map it to Email, and include it in the SAML assertion.
- Grant the pilot user application access and obtain issuer, SAML endpoint, certificate, and metadata from the SSO settings.
For the Microsoft public-cloud workforce ACS, the validator is:
^https:\/\/login\.microsoftonline\.com\/login\.srf$
Verify the persistent subject in the emitted assertion. Avoid permissive ACS wildcard expressions.
Connect Entra and CluedIn
Complete Entra federation, guest onboarding, and CluedIn role assignment. Use the resource tenant associated with your CluedIn SSO connection.
Start the pilot sign-in from CluedIn, verify the correct user and role, then test role changes and logout. Provider roles or groups require an explicit authorization design; forwarding them in SAML does not automatically assign CluedIn roles.
Validate this pattern in your deployment before rollout. The provider application authenticates to Entra; its ACS points to Entra rather than CluedIn.
Troubleshooting
If OneLogin rejects the ACS, check the anchored validator and the actual requested URL. If authentication succeeds but Entra rejects the response, confirm the email parameter is included in SAML and that Persistent was selected instead of the default email format.