Skip to main content

SAML - Azure Guide

VKB-1143How-to
📦 Applies to
Xen Orchestra
🗓️ Created
2025-08-20
🔄 Updated
2025-08-20

Configuring SAML SSO with Azure identity provider to XOA service provider.

Environment​

  • An Azure Entra ID tenant with permissions to create Enterprise applications.
  • A Xen Orchestra instance (XOA) with the auth-saml plugin available.

Procedure​

Azure configuration​

  1. Create a new application:
    • Navigate to: Azure Entra ID > Enterprise applications > New application > Create your own application
    • Set the following:
      • Name: Xen Orchestra
      • Type: Non-gallery
    • Click Create.
  2. Add yourself as a user:
    • Go to: Azure Entra ID > Enterprise applications > Xen Orchestra > Users and groups
    • Add your user account.
  3. Configure SAML:
    • Navigate to: Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML
    • Under Basic SAML Configuration, set:
      • Identifier (Entity ID): https://<XOA URL>/
      • Reply URL (Assertion Consumer Service URL): https://<XOA URL>/signin/saml/callback

Xen Orchestra configuration​

  1. Enable SAML plugin:
    • Navigate to: XO > Settings > Plugins
    • Enable auth-saml.
  2. Set up SAML authentication:
    • Callback URL (callbackUrl): set to https://<XOA URL>/signin/saml/callback
    • Certificate: copy the contents of the Certificate (Base64) from: Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML > SAML Signing Certificate
    • Entry Point: copy the Login URL from: Azure Entra ID > Enterprise applications > Xen Orchestra > Single sign-on > SAML > Set up Xen Orchestra
    • Issuer: copy the Application ID from: Azure Entra ID > Enterprise applications > Xen Orchestra > Properties
    • Username field: set to http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

Verification​

Users assigned to the Xen Orchestra application in Azure can sign in to Xen Orchestra through the SAML SSO flow.