---
title: Microsoft Entra ID | PostGrid
description: Step-by-step instructions for configuring Microsoft Entra ID as a SAML identity provider for PostGrid SSO.
---

This guide explains how to configure Microsoft Entra ID (formerly Azure Active Directory) as the identity provider for PostGrid Single Sign-On (SSO).

## Prerequisites

Before you begin, make sure you have:

- An active PostGrid account on a paid plan
- Administrator access to the [Microsoft Entra admin center](https://entra.microsoft.com/)
- The PostGrid SSO values for your organization

Contact your PostGrid account manager or <support@postgrid.com> to request the organization-specific SSO values before you begin.

## Step 1: Create the enterprise application

1. Open the **Microsoft Entra admin center**.
2. Go to **Identity** → **Applications** → **Enterprise applications**.
3. Select **+ New application**.
4. Select **+ Create your own application**.
5. Enter a name for the application, such as **PostGrid SSO**.
6. Select **Integrate any other application you don’t find in the gallery (Non-gallery)**.
7. Select **Create**.

## Step 2: Configure SAML SSO

1. In the application’s left navigation, select **Single sign-on**.

2. Select **SAML**.

3. In the **Basic SAML Configuration** section, select **Edit**.

4. Enter the values provided by PostGrid:

   - **Identifier (Entity ID)**: PostGrid-provided value
   - **Reply URL (Assertion Consumer Service URL)**: PostGrid-provided value

5. Leave **Sign on URL**, **Relay State**, and **Logout URL** blank unless PostGrid provided specific values for them.

6. Select **Save**.

## Step 3: Configure attributes and claims

In the **Attributes & Claims** section, select **Edit** and verify the following:

- The default **Name ID** uses the user’s email address as the unique identifier.
- Claims for the user’s email address, first name, and last name are included.

Use the claim names and source attributes provided by PostGrid for your configuration. If you do not have those values, confirm them with your PostGrid contact before completing setup.

## Step 4: Get the certificate and identity provider URLs

1. Return to the application’s **Single sign-on** page.

2. In the **SAML Certificates** section, download the **Certificate (Base64)**. Entra ID normally downloads this certificate as a `.cer` file. Rename the file to use a `.cert` or `.pem` extension before sending it to PostGrid.

3. In the **Set up \[PostGrid SSO]** section, copy:

   - **Login URL**
   - **Microsoft Entra Identifier**

## Step 5: Assign users and groups

1. In the application’s left navigation, select **Users and groups**.
2. Select **+ Add user/group**.
3. Select the users or groups who should have access to PostGrid.
4. Select **Assign**.

Users must be assigned to the enterprise application before they can sign in to PostGrid through SSO.

## Step 6: Send the configuration to PostGrid

Send the following information to your PostGrid contact:

- The **Login URL** (Entra ID SSO URL)
- The **Microsoft Entra Identifier** (issuer)
- The **Certificate (Base64)** file
- The email domain or domains to scope to SSO

After PostGrid configures the connection, existing users can sign in through the PostGrid SSO login page. New users must first sign up through the [SSO signup page](https://dashboard.postgrid.com/signup-sso) or accept an SSO invitation from their organization’s owner. Existing PostGrid users must first [migrate their accounts to SAML SSO](/print-and-mail/dashboard/okta-saml-sso-setup/migrate-to-saml-sso/index.md) by signing in with their password and selecting **Switch to SSO** in Settings.
