Unified SSO for Microsoft Entra ID (formerly Azure Active Directory)

👍

Data hub rollout

Engagement customers are being upgraded to unified login in several phases. Your registered support contacts will be notified when the login experience is upgraded for your organization. If your account hasn't been upgraded yet, the pre-existing Administration documentation still applies.

Single sign-on (SSO) authentication for Microsoft Entra ID (formerly Azure Active Directory) lets your team access Bloomreach using their existing company credentials.

This guide explains how to configure Microsoft Entra ID as your identity provider using SAML 2.0 authentication.

Prerequisites

Before configuring SSO in Microsoft Entra ID, ensure you have:

  • Admin role in Bloomreach
  • Admin access to your Microsoft Entra ID identity provider
  • Active SSO feature on your Bloomreach account (contact your Customer Success Manager for activation)

Configure Microsoft Entra ID SSO

To use Microsoft Entra ID SSO login, you must first configure it in the Microsoft Entra admin center.

📘

Info

You will switch between Microsoft Entra and Bloomreach multiple times during this configuration. Keep both dashboards open to streamline the process.

  1. Microsoft Entra ID: Create and set up the enterprise application (Step 1-3).
  2. Bloomreach: Download service provider metadata (Step 4).
  3. Microsoft Entra ID: Upload metadata, configure claims, and get the metadata URL (Steps 5-7).
  4. Bloomreach: Complete the configuration (Step 8).

Step 1: Create an enterprise application

Open the Microsoft Entra admin center and go to Enterprise applications:

  1. Go to Manage > Enterprise applications from the left menu.
  2. Click + New application.
  3. Select + Create your own application.
Azure AD Enterprise Applications page with New application button highlighted.

Creating new application in Microsoft Entra ID Enterprise Applications page.

Step 2: Set up the application

In the modal window, configure your new application:

  1. Enter a name, for example, Bloomreach.
  2. Select Integrate any other application you don't find in the gallery (Non-gallery).
  3. Click Create.
Create application dialog with Bloomreach name and Non-gallery option selected.

Create an application with the application name.

Step 3: Select SAML authentication

Configure SSO for the application:

  1. From the left Manage menu, select Single sign-on.
  2. Choose SAML from the available sign-on methods.
Single sign-on method selection page with SAML option highlighted.

Choose SAML in single sign-on options.

Step 4: Enable SSO and download service provider metadata

Switch to Bloomreach to enable SSO and download service provider metadata:

  1. Go to Administration > Settings > Single sign-on > Preferences.
  2. Enable the Single sign-on integration toggle.
  3. Click Download service provider metadata.
  4. Save the file as service-provider-metadata.xml
Bloomreach SSO settings with Download service provider metadata button highlighted.

Enable SSO and download service provider metadata from Bloomreach settings.

Step 5: Upload metadata

Return to the Microsoft Entra admin center and:

  1. Click Upload metadata file.
  2. Select the XML file you downloaded from Bloomreach.
  3. Review the Basic SAML Configuration extracted from the metadata.
  4. Click Save.
Azure AD SAML configuration with Upload metadata file button highlighted.

Upload metadata to Microsoft Entra ID.

Step 6: Configure attributes and claims

Set up the required user attributes for authentication:

  1. Go to the Attributes & Claims section.
  2. Click Edit.
Azure AD Attributes and Claims section with Edit button highlighted.

Attributes and claims in Microsoft Entra ID.

  1. Remove all Additional claims (keep the Required claim unchanged).
  2. Add the following three new claims using + Add new claim.
Claim nameSourceSource attribute
emailAttributeuser.userprincipalname
first_nameAttributeuser.givenname
last_nameAttributeuser.surname

Optional claims:

  • Add a mobile phone claim (user.mobilephone) if mobile phone data is available.
  • Add an email address claim (user.email) and a unique name ID claim if users can't receive emails to the addresses defined in user.userprincipalname.
Attributes and Claims page with Add new claim button highlighted.

Add a new claim to Microsoft Entra ID.

Step 7: Get metadata URL

Get the metadata URL from the Microsoft Entra admin center:

  1. Go to SAML Signing Certificate.
  2. Copy the App Federation Metadata URL to your clipboard. You'll need it in the next step.
SAML Signing Certificate panel showing App Federation Metadata URL.

Copy the App federation metadata URL to the clipboard.

Step 8: Complete the configuration

Finish the configuration in Bloomreach:

  1. Go to Administration > Settings > Preferences.
  2. Paste the URL into the Metadata URL field under Identity provider metadata.
  3. Click Apply URL.
  4. Verify that the metadata contains a valid single sign-on URL and that the encryption and signing certificates haven't expired.
  5. Click Save changes.
Bloomreach Identity provider metadata configuration with certificate details.

Paste the metadata URL to Bloomreach.

Then enable SSO as an allowed authentication method:

  1. Go to Administration > Settings > Security > Authentication settings.
  2. Enable single sign-on as an allowed authentication method.
  3. Optionally disable other authentication methods to enforce SSO.
  4. Click Save changes.
Bloomreach Authentication settings with Single sign-on checkbox highlighted.

Enable SSO in Bloomreach.

All users you assign to the application in Microsoft Entra ID can now log in to Bloomreach and access their subscribed Bloomreach products using SSO.

Next steps

  1. Assign users to the application in Microsoft Entra ID.
  2. Assign user roles via SSO (see Unified SSO authorization for Microsoft Entra ID).
  3. Test the SSO login with a test user.
  4. Communicate the change to your team.

© Bloomreach, Inc. All rights reserved.