# How to configure SAML authentication settings in Endpoint Central? **Last Updated On**: 22 Jul 2026 **4 minutes read** ## Description This document will walk you through the steps required to configure SAML Authentication settings in Central Server for Azure. > **Note**: If the FQDN in the ACS URL is different from the one mentioned in the **NAT Settings**, then go to `/Endpoint Central server/conf/websettings.conf` and, in a new line, type **saml.fqdn.name=FQDN_Name**. > Here, **FQDN_Name** represents your FQDN name. > > For example: `saml.fqdn.name=dc.com`. Here, **dc.com** is the FQDN name. > > After saving the **websettings.conf** file, restart the **Central Server** server and reconfigure the **SAML Authentication** settings. ## Installation Steps 1. Login to your Azure account using **https://portal.azure.com** and enter your email address. After that, click **Next**. ![Login to your Azure account](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-01.webp) 2. Enter the **password** and click **Sign in**. ![enter your Azure account password](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-02.webp) 3. Select **Enterprise applications**. ![Select Enterprise Application](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-04.webp) 4. Select **New application**. ![Select New Application](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-05.webp) 5. On the left hand side, select **+ Create your own application**. ![Azure Create your own application](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-crtapp.webp) 6. Select **Non-gallery application** on the right hand side. ![Azure select Non-gallery application](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-06.webp) 7. Provide an appropriate app name and click **Create**. ![Azure Provide an appropriate app name and click](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-07.webp) 8. On the left hand side menu, click **Single sign-on**. ![SAML Authentication settings for Azure](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-08.webp) 9. Select **SAML**. ![SAML Authentication settings for Azure](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-09.webp) 10. In **Basic SAML Configuration**, select edit option (the pencil icon). ![Azure select edit option (the pencil icon)](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-10.webp) 11. In this window, the **Entity ID**, **Assertion Consumer Service URL**, and the **Sign on URL** have to be specified. ![Azure Assertion Consumer Service URL, Sign on URL](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-11.webp) 12. Login to your **Central Server** console, switch to the **Admin** tab, and select **SAML Authentication**. ![Login to your central server console, switch to the Admin tab](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-12.webp) 13. Choose **Certificate** next to **Configuration by downloading**. Copy the **Entity ID** and **Assertion Consumer URL**. ![Azure Choose Certificate next to Configuration by downloading.](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-13.webp) 14. Paste the **Entity ID** next to **Identifier**, and the **Assertion Consumer URL** next to **Reply URL** in the **Microsoft Azure** portal. ![Azure Paste the Entity ID next to Identifier, and the Assertion Consumer URL](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-14.webp) 15. Now, copy the **Assertion Consumer URL** and paste it next to **Sign on URL**. Here, change the URL from **Response** to **Request** and click **Save**. ![Azure copy the Assertion Consumer URL and paste it next to Sign on URL](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-15.webp) 16. In **User Attributes & Claims**, select edit option (the pencil icon). ![Azure User Attributes & Claims](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-16.webp) 17. Click **user.userprincialname [nameid-f...]**. ![Click user.userprincialname [nameid-f....](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-17.webp) 18. Click **user.userprincipalname**. ![Azure click user.userprincipalname](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-18.webp) 19. In the drop-down list, select **user.mail**. ![Azure In the drop-down list, select user.mail.](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-19.webp) 20. Click **Save**. ![Azure click save](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-20.webp) 21. In **SAML Signing Certificate**, download **Federation Metadata XML**. ![Azure download Federation Metadata XML.](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-21.webp) 22. On the left hand side menu, click **Users and groups**. Select **Add user**. ![Azure click Users and groups. Select Add user.](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-22.webp) 23. Click **None Selected**. ![Azure click None Selected](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/user-management/saml-azure-23.webp) 24. From the right hand side, select the users and click **Select**. ![Azure Select User](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-24.webp) 25. Click **Assign**. ![Azure click Assign](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-25.webp) 26. In the Central Server web console, under **Identity Provider Details**, choose **Others** as **IdP**. Provide a suitable name for the **IdP**, and choose **E-mail ID** as **Name ID**. Next, select **Metadata** and upload the downloaded metadata file in step 21. Click **Save**. ![SAML Authentication central server identiy provider details](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-26.webp) 27. **SAML Authentication** is now enabled in **Central Server**. ![SAML Authentication Detail page in central server](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-27.webp) 28. Login to **Central Server** using your Azure account. ![Central server Login page](https://cdn.manageengine.com/sites/meweb/images/desktop-central/help/tools/saml-azure-28.webp) You have successfully configured the SAML Authentication Settings.