How to Set Up Single Sign-On (SSO) Using Azure AD for Your Avoma Accounts
Use Avoma's SSO with Azure AD SAML Integration for streamlined access management and unified login experience for your users
Avoma supports Single Sign-On (SSO) with Azure Active Directory (Microsoft Entra ID) to give your organization a unified and secure way to manage user access. With SSO enabled, employees can log in to Avoma using their corporate credentials, reducing password fatigue and strengthening security. SSO works based upon a trust relationship set up between an application, known as the service provider, (in this case Avoma) and an IDP (identity provider), like Okta, Azure AD, Jumpcloud etc.
This help article documents the process of setting up SSO with Azure AD using the SAML 2.0 protocol for your Avoma account.
Prerequisites
Before you begin, make sure that:
- You are on the Organization plan or higher in Avoma.
- You have Admin privileges in Avoma to request SSO setup.
- You are an Azure AD administrator with one of these roles: Cloud Application Administrator or Application Administrator.
Note: Once SSO is enabled for your organization:
- Users will only be able to log in using SSO.
- Other login methods, such as Google or Microsoft sign-in, will be disabled.
Setting up SSO for Avoma with Azure AD SAML is two step process
- Create an Enterprise application for Avoma SSO in Azure portal
- Provide details to set up Azure AD SAML SSO in Avoma
Step 1 : Create an Enterprise application for Avoma SSO in Azure Portal
- Sign In to Azure Portal and navigate to Home > Enterprise applications > All applications. Create “New Application”.  
- Click on Create your own application.  Give it a unique name such as Avoma SSO and click on Create.   
- Select “Setup Single Sign On” and select “SAML”. 
- Fill following fields in the SAML-based Sign On - Basic SAML Configuration
- Identifier ( Entity Id) - https://app.avoma.com
- Reply URL (Assertion Consumer Service URL) - https://prod-api.avoma.com/saml2/acs
- Relay State - https://app.avoma.com
- Click Save 
 
- Copy the App Federation Metadata Url ,  save it somewhere. This information will be needed to be sent to Avoma team to setup SSO 
- Copy Microsoft Entra Identifier ,  save it somewhere. This information will be needed to be sent to Avoma team to setup SSO 
- Now go to the Users and Groups and assign the app to appropriate users
Step 2: Provide details to set up Azure SAML SSO in Avoma
Currently, Avoma sets up an SSO on your behalf for your organization. Please contact Avoma Support or your Customer Success Manager and provide the following details:
- App Federation Metadata Url copied in Step 1 - #5
- Microsoft Entra Identifier set in Step 1 - #6
Once Avoma has configured SSO for you, you will receive a confirmation. Avoma will also terminate the existing sessions for all your users so that they can freshly log in using SSO. Going forward all the users from your organization will only be able to login via SSO.
Your users can then start using the SSO option on the Avoma login screen to access their accounts.
![Avoma_Logo_Dark_Large-1.png]](https://help.avoma.com/hs-fs/hubfs/Avoma_Logo_Dark_Large-1.png?height=23&name=Avoma_Logo_Dark_Large-1.png)