docs-mintlify/admin/sso/microsoft-entra-id/saml.mdx
With SAML (Security Assertion Markup Language) enabled, you can authenticate users in Cube through Microsoft Entra ID (formerly Azure Active Directory), allowing your team to access Cube using single sign-on.
<Note>Available on Enterprise plan.
</Note>Before proceeding, ensure you have the following:
First, enable SAML authentication in Cube:
Return to the SAML configuration page in Cube and provide the identity provider details. You can do this in one of two ways:
Option A: Upload metadata file
Option B: Enter details manually
If you prefer to configure the fields manually, enter the following values from the Entra Single sign-on page:
In both options, also configure the following setting:
Auto-provisioned users — both via SAML and via SCIM — receive the Viewer role by default. To assign a different role, expand the Advanced section of the SAML configuration form and pick from Default role for new users:
The selected role applies only when a user is first created during
provisioning. Existing users are not modified on subsequent SSO logins or
SCIM updates. It is applied in addition to any roles your identity
provider sends via the role attribute
(subject to the rolesMap).
Admin status is not assignable through this picker — Admin is controlled separately. To grant admin permissions, update the user's role manually under Admin → Users.
</Info> <Warning>If the selected role is later renamed or deleted, new users will fall back to the Viewer role until you pick a valid role here. The Viewer fallback applies whenever the configured default cannot be resolved — whether that's because no default is set or the configured role no longer exists.
</Warning>To map user attributes from Entra to Cube, configure the claim URIs in the SAML settings:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddresshttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameAdmin status cannot be set via SSO. To grant admin permissions, update the user's role manually in Cube under Team & Security.
</Info>Make sure the new Enterprise Application is assigned to the relevant users or groups in Entra before testing.