Entra ID (Azure AD) SAML
Last Updated: August 18, 2026
An identity provider (IdP) uses an authentication token to vouch for a person's identity. Vasion Automate uses IdPs for several tasks, including logging in to the Admin Console and portals, deploying printers, releasing print jobs, and more.
If you use an IdP, the Control Panel Application (CPA) supports only badge and PIN authentication.
Key Points
Review the following key point:
- The default values in the Entra ID 2. Attributes & Claims section should not be adjusted. Changing these will cause issues with user authentication.
- If you use Azure Government, including Government Community Cloud (GCC) High, you cannot use the PrinterLogic Entra ID gallery application. Instead, create a custom app in step 1.
Requirements
Review the following requirements:
- Access to the Microsoft Entra admin center.
- One of the following roles: Global Administrator, Cloud Application Administrator, Application Administrator, or owner of the service principal.
- Configuration of the enterprise app properties in Entra ID.
- Vasion admin rights.
Configure Connection
To add and configure enterprise app properties for the Vasion Automate connection, do the following:
- Create the Entra ID App.
- Add the IdP Information Template.
- Configure Single Sign-On (SSO).
- Add the X-509 Certificate.
- Configure Provisioning.
- Add PrinterLogic Admins.
1. Create the Entra ID App
To create the app:
- In your preferred browser, go to the Microsoft Entra admin center at https://entra.microsoft.com/#home, and log in.
-
From the left-side navigation, expand Entra ID, and select the Enterprise apps option.
-
Select + New application.
- There are two options here.
- Search for and select the PrinterLogic gallery app.
- Or select + Create your own application.
- Give your app a unique name, and select Create.
Leave the current browser on the new app page. To continue app configuration, open the Vasion Automate or PrinterLogic Admin Console in a new browser, and access the service provider information.
2. Add the IdP Information Template
In a separate browser window, log in to Vasion Automate, and do the following:
- Select Admin from the left-side navigation.
- Select the Authentication option.
-
Select the + New Authentication button.
- Select the IdP that you want to configure.
- Select Next.
- Give your IdP a unique name.
- (Optional) Add a description.
- Select SAML2 in the Authentication Protocol section.
-
In the Provisioning section, if you are using Systems for Cross-domain Identity Management (SCIM), leave the Just-in-Time (JIT) option deselected.
- Leave the IdP Information page open. You need this information for the next step.
3. Configure Single Sign-On (SSO)
Return to the Entra ID browser, and do the following:
- Go to the Entra ID (Azure AD) app you created.
- On the Overview tab, select Get started in the 2. Set up single sign on section.
- In the Select a single sign-on method section, select SAML.
- In the Set up Single Sign-On with SAML section, select Edit in the 1. Basic SAML Configuration section.
- On the Basic SAML Configuration page, complete the following steps:
- Select Add identifier in the Identifier (Entity ID) section. Then copy the Vasion Admin Console Identifier (Entity ID) URL, and paste it in the Entra ID Identifier (Entity ID) field.
- Select Add reply URL in the Reply URL (Assertion Consumer Service URL) section. Then copy the Admin Console Reply Url (ACS) URL, and paste it in the Entra ID Reply URL (Assertion Consumer Service URL) field.
- Copy the Admin Console Relay State URL, and paste it in the Entra ID Relay State (Optional) field.
- Select Save at the top, and then select the Close button.
- Scroll down to 4. Set up <App Name>, and copy the Login URL.
- Paste the Login URL in the Admin Console SSO URL field.
- Press Tab while in that field to autopopulate the Issuer URL and Issuer ID fields.
- Do the following if the fields do not autopopulate:
- On the Single sign-on tab in the Entra ID app, scroll down to the 4. Set Up <App Name> section.
- Copy the Microsoft Entra Identifier, and paste it in the Admin Console Issuer URL field.
- In the Issuer URL field, cut the alphanumeric portion after the slash (/), and paste it in the Issuer ID field.
- Issuer URL example: https://abc1234.my.idaptive.app/.
- Issuer ID example: a1b2cd34-fb1f-4f71-9248-8675309d/.
4. Add the X-509 Certificate
Follow these steps:
- Return to the Entra ID browser, scroll to the 3. SAML Certificates section, and select the Download link for Certificate (Base64).
- Open the file in your preferred text editor.
-
Copy the certificate body, including the Begin and End Certificate headers, and paste it in the Admin Console X509 Certificate field.
- Select Save in the upper-right corner.
5. Configure Provisioning
The provisioning steps vary depending on whether you are using SCIM or Just-in-Time (JIT) provisioning. Choose the appropriate option below to view the corresponding steps.
SCIM Provisioning
Configure SCIM Provisioning
Follow these steps:
- In Entra ID select Provisioning.
- Do one of the following:
-
Copy the Vasion Admin Console SCIM Tenant URL from the Service Provider Information section, and paste it in the Entra ID Tenant URL field.
- In the Admin Console IdP Information page, select the Generate New Token button in the SCIM Token section.
- Copy the SCIM token, and paste it into the Entra ID Secret token field.
- Select the Test connection button to confirm the connection, and then select Create.
- From the left-side Manage menu, select Provisioning.
- In the Provisioning Status section, select On.
- Select Save.
The initial provisioning can take up to 45 minutes to automatically provision after you make changes. Select the Start Provisioning option on the Entra ID Provisioning tab to start the process sooner.
Add Users & Groups
Follow these steps:
- In Entra ID select Users and groups from the left-side Manage menu.
- Select the + Add user/group option.
- In the Users and groups section of the Add Assignment page, select None Selected.
- Add the users and groups that you want to provision over.
- Select the Select button.
- The Users role applies automatically.
- Select Assign.
Nested groups, or sub-groups within another group, are not supported and do not provision over. You need to adjust any nested groups that you want to provision.
Turn On the IdP
Follow these steps:
JIT Provisioning
JIT does not support the provisioning of group membership associations, so you cannot apply Role-Based Access Control (RBAC) roles, printer deployments, or portal security roles to groups. You must create assignments individually for each user.
Turn On the IdP
Follow these steps:
- In Vasion Automate, close the IdP Information page.
- In the Authentication page, select the button next to the configured IdP to turn it on.
Create Users
When using JIT provisioning, the app creates users during the first sing-in attempt:
- Access your Vasion instance, and select Sign In With <IdP Name>.
- Attempt to sign in with your IdP credentials.
-
This sign-in attempt fails and returns you to the sign-in screen.
This behavior is expected. With JIT, this action triggers user creation in the Vasion instance.
- The second sign-in attempt with valid credentials initiates a typical sign-in sequence.
For admins who need access to the Admin Console, you still need to add them to the Users page located in Tools
Users.
6. Add PrinterLogic Admins
For steps on assigning users and roles to the PrinterLogic and Vasion Automate Admin Console, refer to Admin Console Users.
In this topic:









