Set up Microsoft Azure (Entra) SSO for 8x8 Admin Console

Prev Next

Microsoft Azure (Entra) SSO lets your users sign in to 8x8 applications with their Microsoft Azure (Entra) credentials, using SAML 2.0.

Users are matched to their 8x8 account by Federation ID. By default, this is the user's 8x8 username. See Identity mapping on the Set up Single Sign-On for 8×8 Admin Console page and Configure Federation ID or Google ID in user records.

Prerequisites

Add the 8x8 application in the Microsoft Azure (Entra) admin center and obtain the required values directly on the Microsoft platform. For detailed instructions, consult Microsoft's official documentation. You will need to retrieve the following details from Azure to configure in 8x8:

  • The Azure Login URL

  • The Azure AD Identifier (issuer)

  • The Azure Logout URL (optional)

  • The SAML signing certificate, in Base64 format

Add Microsoft Azure (Entra) in 8x8 Admin Console

  1. Sign in to 8x8 Admin Console.

  2. Go to Home > Identity and Security.

  3. Enable Single Sign-On (SSO).

  4. Click + Add SSO.

  5. In the Add a new Single Sign-On (SSO) integration window, complete the following settings:

    1. Select Microsoft Azure (Entra) as the identity provider.

    2. Optional: Turn on Set this provider as default.

    3. Under Label your provider, provide a distinct descriptive name for this provider. This label identifies the provider when admins assign it to users, so clear names prevent confusion.

    4. Sign-in page URL: Paste the Azure Login URL.

    5. IDP Issuer URL/URN: Paste the Azure AD Identifier.

    6. Sign-out page URL (optional): Paste the Azure Logout URL. To return users to the 8x8 sign-in page after they sign out, append the {8x8Logout} variable.

    7. Certificate in use: Attach the Base64 certificate you downloaded from Azure.

  6. Click Add.

  7. Click Save on the Identity and Security page.

Administrator configuring Microsoft Azure AD SSO integration with label and SAML sign-in/sign-out URLs

Select Microsoft Azure AD as the identity provider, then label the integration and enter the SAML sign-in and sign-out page URLs