Skip to main content

Configure SAML SSO between DigiCert and Microsoft Entra ID

Use this procedure to configure single sign-on (SSO) between your DigiCert​​®​​ account and Microsoft Entra ID using Security Assertion Markup Language (SAML) 2.0.

To set up this sign in method, you need to switch between two tabs, DigiCert and Microsoft Entra, to exchange metadata.

For more details about Microsoft Entra configuration, refer to Microsoft Learn.

Before you begin

To finish this setup, you need administrative access in both DigiCert and Microsoft Entra:

  • Account admin user group required in DigiCert account.

    How do I check my user group?

  • Application Administrator or equivalent role required in Entra.

Access DigiCert's SAML configuration page and download DigiCert’s metadata file that you need to provide to Entra in Step 2.

  1. In DigiCert​​®​​ account, select Accounts () > Identity and access.

  2. Select Single sign-on with SAML.

  3. In the Connect DigiCert to your IdP section, select Download DigiCert metadata.

  4. Leave this tab open.

In another tab, create a SAML application for your DigiCert account:

  1. Sign in to the Microsoft Entra admin center.

  2. In the left pane, select Microsoft Entra ID.

  3. In the left pane of Microsoft Entra ID, select Manage > Enterprise applications.

  4. Select New application.

  5. In the Search application field, enter DigiCert.

  6. Select the application for DigiCert, Inc.

  7. In the Name field, change the name to DigiCert account.

  8. Select Create.

  9. In the left pane, select Manage > Single sign-on.

    1. To exchange metadata between Entra and DigiCert:

      1. Select Upload metadata file to upload DigiCert's metadata downloaded in Step 1.3.

      2. Go to the SAML Certificates section.

      3. Select Download next to Federation Metadata XML.

    2. Go to the Attributes & Claims section.

      1. Select Edit (✎)

      2. Select Add new claim.

        Attribute

        Claim value

        Notes

        givenName

        user.givenName

        User first name

        surname

        user.surname

        User last name

        emailAddress

        user.mail

        User email address

        name

        user.userPrincipalName

        Entra username (used as the username to sign in to DigiCert​​®​​ account)

        unique user identifier

        user.userPrincipalName

        Entra username, also referred to as UPN.

  10. Leave this tab open.

Back in your DigiCert​​®​​ account tab, upload the Entra metadata that you downloaded in Step 2 and enable SSO:

  1. In the Connect your IdP to DigiCert section, select Upload IdP metadata.

  2. In the Enable/Disable SSO with SAML section, switch to enable SSO.

  3. Select Save configuration.

Ensure that all users in your DigiCert account are also assigned to the SAML application in Microsoft Entra admin center:

  1. Go to Manage > Enterprise applications.

  2. Select the DigiCert account application you created.

  3. From the application's overview, select Assign users and groups.

  4. Select +Add user/group.

Verify that you’re able to sign in using your SAML application from Microsoft Entra admin center:

  1. Go to Manage > Enterprise applications.

  2. Select the DigiCert account application you created.

  3. Select Manage > Single sign on.

  4. Select Test this application.

  5. Select Test sign in.

  6. On the Success page, select Done.

  7. On the Let's keep your account secure page, select Next.

  8. On the second Success page, select Done.

  9. On the second Let's keep your account secure page, select Next.

    Dica

    • Your SAML app is configured correctly if you’re redirected to your DigiCert account and asked to finish two-factor authentication (2FA).

    • Not redirected to the 2FA page in your DigiCert account? Compare your SAML app settings to these instructions or contact DigiCert Support for assistance.

DigiCert logos

Download one of the following logos to help you identify your DigiCert​​®​​ account SAML app in your IdP:

DigiCert_White_on_Blue_Logo.png
DigiCert_Blue_on_White_Logo.png

DigiCert logos for SSO configuration.

Use of DigiCert's logo must at all times comply with DigiCert brand guidelines, including the DigiCert Trademark Usage Guidelines available at https://www.digicert.com/legal-repository/ (as updated from time to time).