Azure Active Directory - Entity ID - SSO

Arroyo, Renee 116 Reputation points
2020-10-16T18:49:13.007+00:00

I have 12 IBM applications that are to be configured as SSO all having the same Entity ID and ACS. The unique attribute is the relay state. Since Azure requires a unique entity ID/ACS for each application, how can this be done. I attempted to configure thru application registration, but there isn't a field to enter the relay state. Can this be done? Much appreciated!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

Accepted answer
  1. Arroyo, Renee 116 Reputation points
    2020-10-22T19:58:28.953+00:00

    This is not good news. Unfortunately, the flow will be IDP. This was not an issue with Okta so I would hope that these types of customizations will be forthcoming in Azure.

    1 person found this answer helpful.

4 additional answers

Sort by: Most helpful
  1. JamesTran-MSFT 36,906 Reputation points Microsoft Employee Moderator
    2020-10-22T18:08:37.597+00:00

    @Arroyo, Renee
    Thank you for your time and patience, I received a response from our product team and will post it below.

    PG response:
    It should work if you're using SP initiated flow and will add ?RelayState= to the request. For IdP initiated flow we only support one relay state.
    You should be able to do this following the OASIS Security Assertion Markup Language (SAML) V2.0 Technical Overview

    If you have any other questions, please let me know.
    Thank you again for your time and patience throughout this issue.

    0 comments No comments

  2. Randall Brownlee 1 Reputation point
    2021-07-29T21:09:37.027+00:00

    @Arroyo, Renee -> Hello, did you ever wind up finding a solution in Azure for the exact scenario you're facing above?

    0 comments No comments

  3. Phil Jackson - ADMIN 6 Reputation points
    2021-08-17T15:38:35.673+00:00

    This is an issue for me now. I am trying to migrate from Okta, and now I am hindered as I can't setup multiple VPN profiles, because they don't want the saml profile to have the same entity ID. This should be a simple fix to put in place. Okta did it perfectly.


  4. Vidhya Athmanathan 0 Reputation points
    2023-05-17T17:03:02.95+00:00

    I am encountering the same issue. I stumbled upon this thread. Any luck - anyone on getting this resolved with Azure? Thank you for your help.

    Thanks,

    -Vidhya

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.