SAML - Azure Guide
VKB-1143How-to
- 📦 Applies to
- Xen Orchestra
- 🗓️ Created
- 2025-08-20
- 🔄 Updated
- 2025-08-20
- 🏷️ Tags
Configuring SAML SSO with Azure identity provider to XOA service provider.
Environment
- An Azure Entra ID tenant with permissions to create Enterprise applications.
- A Xen Orchestra instance (XOA) with the auth-saml plugin available.
Procedure
Azure configuration
- Create a new application:
- Navigate to:
Azure Entra ID > Enterprise applications > New application > Create your own application - Set the following:
- Name: Xen Orchestra
- Type: Non-gallery
- Click Create.
- Navigate to:
- Add yourself as a user:
- Go to:
Azure Entra ID > Enterprise applications > Xen Orchestra > Users and groups - Add your user account.
- Go to:
- Configure SAML:
- Navigate to:
Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML - Under Basic SAML Configuration, set:
- Identifier (Entity ID):
https://<XOA URL>/ - Reply URL (Assertion Consumer Service URL):
https://<XOA URL>/signin/saml/callback
- Identifier (Entity ID):
- Navigate to:
Xen Orchestra configuration
- Enable SAML plugin:
- Navigate to:
XO > Settings > Plugins - Enable auth-saml.
- Navigate to:
- Set up SAML authentication:
- Callback URL (callbackUrl): set to
https://<XOA URL>/signin/saml/callback - Certificate: copy the contents of the Certificate (Base64) from:
Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML > SAML Signing Certificate - Entry Point: copy the Login URL from:
Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML > Set up Xen Orchestra - Issuer: copy the Application ID from:
Azure Entra ID > Enterprise applications > Xen Orchestra > Properties - Username field: set to
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- Callback URL (callbackUrl): set to
Verification
Users assigned to the Xen Orchestra application in Azure can sign in to Xen Orchestra through the SAML SSO flow.
Was this page helpful?