docs/content/product/administration/sso/microsoft-entra-id/saml.mdx
With SAML (Security Assertion Markup Language) enabled, you can authenticate users in Cube through Microsoft Entra ID (formerly Azure Active Directory), allowing your team to access Cube using single sign-on.
<InfoBox>Available on Enterprise and above plans.
</InfoBox>Before proceeding, ensure you have the following:
First, enable SAML authentication in Cube:
Return to the SAML configuration page in Cube and provide the identity provider details. You can do this in one of two ways:
Option A: Upload metadata file
Option B: Enter details manually
If you prefer to configure the fields manually, enter the following values from the Entra <Btn>Single sign-on</Btn> page:
To map user attributes from Entra to Cube, configure the claim URIs in the SAML settings:
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddresshttp://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameAdmin status cannot be set via SSO. To grant admin permissions, update the user's role manually in Cube under <Btn>Team & Security</Btn>.
</InfoBox>Make sure the new Enterprise Application is assigned to the relevant users or groups in Entra before testing.