> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://helpdesk.ggcircuit.com/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# 🧑‍💼 SAML SSO -  How to Set Up Microsoft Entra ID (Azure AD)

1. **Download the SAML Metadata File**

* Go to [https://sp.ggleap.com/](https://sp.ggleap.com/)
* Right-click the link on the page and choose **“Save link as…”**
* Save the file as an **XML file** to your local machine
2. **Log In to Azure**

* Go to the [Azure Portal](https://portal.azure.com/)
* Log in with your Azure administrator account
3. **Set Up SAML in Azure**

* Navigate to your application in Azure AD
* 

     ![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860397/undefined-Jul-31-2023-03-02-48-8511-PM.png?version=3&modificationDate=1745084347087&cacheVersion=1&api=v2)
* Go to **Single Sign-On** > Choose **SAML**
* Upload the downloaded **XML metadata file**

     ![](https://ggcircuit.atlassian.net/wiki/download/attachments/15860397/undefined-Jul-31-2023-03-02-48-0391-PM.png?version=2&modificationDate=1745084376935&cacheVersion=1&api=v2)
* Click **Save**
4. **Configure ggLeap Web Admin**

* Copy the **App Federation Metadata URL** from Azure
* Go to the **ggLeap Web Admin > Add-Ons Marketplace > Saml SSO Add-on** page
     ![](https://storage.crisp.chat/users/helpdesk/website/-/a/f/d/6/afd6941e8bc7d800/image_ru8tpf.png)
![](https://storage.crisp.chat/users/helpdesk/website/-/a/f/d/6/afd6941e8bc7d800/image_pr4woz.png)


* Enable the **Single Sign-On (SSO) Add-on.**
* Enable <YOUR INSTITUTION NAME> is an incommon federation participant if your institution is a part of incommon.
* Paste the **App Federation Metadata URL into the "Metadata URL" text field.**
* Enter the SSO configuration ID if your institution's IdP hosts more than one SSO configuration and requires this parameter.
* Click **Save**
---

### 📝 Notes:

* The user’s **email must not already exist** in another ggLeap center
* **Universities** should use email addresses with their **institution’s domain**
* A user account will be automatically created in ggLeap Web Admin upon first sign-in
* For info on **free time assigned to accounts**, [click here](https://chatgpt.com/c/6803da71-4a94-8009-a38f-c3d80b368632#) (← replace with actual link)

---