---
title: "Configure Microsoft Entra for AIM"
canonical: "https://docs.aryaka.com/space/KNOW/203325458/Configure%20Microsoft%20Entra%20for%20AIM"
format: markdown
---
This document explains how to configure your Microsoft Entra identity provider (IdP) to synchronize users and user groups between Microsoft Entra and MyAryaka.  To edit or delete an existing configuration, see the  Manage Entra SAML  topic. Some of the procedures described in this document are performed in the Microsoft Entra administrator interface (known as the  Microsoft Entra   admin center ). While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the Microsoft Entra UI are beyond our control. Refer to the documentation provided by Microsoft to ensure you have the most recent information. Prerequisites MyAryaka account with read and write access Microsoft Entra administrator account Configure identity authentication using Microsoft Entra SAML in MyAryaka Complete the procedure described in this section to add a Microsoft Entra instance to your Aryaka Identity Management configuration and obtain SAML settings required for subsequent configuration. To configure identity authentication using Microsoft Entra SAML in MyAryaka Go to MyAryaka at  https://my.aryaka.com/ . The MyAryaka Login page appears. Log in using your MyAryaka credentials. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Entra tile in the Available Identity Providers section. The Configure Enterprise’s Entra page appears and displays the following panes: SAML Identity and Provider Pre-configuration steps for SAML Entra SAML Details In the SAML Identity and Provider section, enter a name for this Entra instance in the Enterprise’s Entra Name field. Note that you can create multiple Entra instances. The fields in the Pre-configuration Steps for SAML section are automatically populated. These fields are required for the Entra SAML configuration described in step 7 in the next section. We recommend leaving this page open, as there are more configuration tasks that you must perform here after working in the Microsoft Entra admin center, as described in the next section.  Configure Aryaka as an Entra application Complete the procedure described in this section to configure SAML-based SSO and create an application in Microsoft Entra called  Aryaka Identity Management . Then, complete the procedure to configure API permissions . To configure SAML SSO in Microsoft Entra Log in to the Microsoft Entra admin center as an administrator.  Click  Applications  >  Enterprise Applications  in the left navigation pane. The Enterprise applications | All applications page appears with the application catalog displayed by default: Click  New Application . The Browse Microsoft Entra Gallery page appears. Click  Create your own application . The Create your own application pane appears: Enter a name for the new application, for example: Aryaka Pilot. Select the  Integrate any other application you don't find in the gallery (Non-gallery)  option. Click  Create . The new application is created, and its Home page appears.  In the new application’s home page, click  Single sign-on  in the left navigation pane. The Single sign-on page appears:  Click the  SAML  tile. The SAML-based Sign-on page appears:   Perform the following steps in the Basic SAML Configuration pane using the information obtained from MyAryaka (described in step 6 of the previous procedure):  Enter the new application’s unique ID in the  Identifier (Entity ID ) field, for example: https://aim.aryaka.com/realms/c2753.  Enter the URL where the new application expects to receive the authorization token in the  Reply URL (Assertion Consumer Service URL)  field. This URL is also known as the  Assertion Consumer Service  (ACS) URL in SAML, for example: https://aim.aryaka.com/realms/c2753/broker/saml/endpoint. Click  Edit  (top right of this pane). The Basic SAML Configuration dialog appears with your entries (from steps a and b) displayed in the corresponding fields: Confirm that the two required URLs (in the Identifier and Reply URL fields) display a check to the right of each URL. This indicates that Microsoft Entra validated the format and characters in the corresponding URL. Click  Save  (top left). The SAML configuration is saved and the SAML-based Sign-on page appears again. In the SAML Certificates pane, click  Download  in the Federation Metadata XML field to download the metadata XML file: The file uses the name entered in step 4a of this procedure (for example, Aryaka_Pilot.xml) and is saved to your computer’s default download location. To configure API permissions for an application in Microsoft Entra Log in to the Microsoft Entra admin center as an administrator.  Navigate to  App registrations  >  All applications  in the left navigation pane. Select the application you need to configure API permissions for.  Click  Add a permission .  Select  Microsoft APIs , then  Microsoft Graph . Select  Application permissions , then add the following permissions: Group.Read.All—Grants permission to read all user groups. GroupMember.Read.All—Grants permission to read all group memberships. User.Read.All—Grants permission to read all users' full profiles. Select  Delegated permissions , then add the following permissions: User.Read—Grants permission to sign in and read a user’s profile. Click  Grant admin consent for < tenantName > .  Confirm that the  Status  column shows  Granted  for the following permissions: Group.Read.All GroupMember.Read.All User.Read User.Read.All Configure SAML in MyAryaka Complete the procedure described in this section to configure SAML in MyAryaka. You must provide the metadata file obtained in the previous procedure. To configure SAML in MyAryaka If it is not already open, navigate to the Configure Enterprise’s Entra page: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Add  on the Enterprise’s Entra tile in the Available Identity Providers section. The Configure Enterprise’s Entra page appears. In the Entra SAML Details section, click  Upload File , click  Browse , and then navigate to the metadata XML file that you downloaded in step 8 of the previous procedure. Enter the user domain that must be redirected to this instance of Entra in the IdP Redirect Domain field. Click  Submit . MyAryaka obtains the Identity Provider Entity ID and Single Sign-On Service URL from the selected file and displays them in the Entra SAML Details pane of the < IdPname > page. Obtain identifiers in Microsoft Entra Complete the procedure described in this section to obtain identifiers in Microsoft Entra that are used by the Aryaka Identity Management system to authenticate with Microsoft Entra and obtain user and user group data. To obtain identifiers in Microsoft Entra Log in to the Microsoft Entra admin center as an administrator. Click  Applications  >  Enterprise Applications  in the left navigation pane. The Enterprise applications | All applications page appears with the application catalog displayed by default. Copy or note the following three identifiers for the newly-created Aryaka application: Application ID—Located in the applications table on the Enterprise applications | All applications page. This system-generated Application ID is referred to as the Client ID in MyAryaka (as described in step 3 in the next section). Value—Navigate to  App registrations  >  All applications  in the left navigation pane. Select  Aryaka Pilot , then click  + New client secret  under Certificates & Secrets. Provide a description and expiry, then click  Add . You must immediately copy the Value (not the Secret ID), as it is permanently masked by asterisks once you leave or refresh the page. This system-generated Value is entered in the Client Secret field in MyAryaka (as described in step 4 in the next section). Tenant ID—Located on the Overview tab of the Home > Overview page. This system-generated ID identifies your organization and is not an application-specific ID. You must enter this ID in the Tenant ID field in MyAryaka (as described in step 5 in the next section).    Configure user and group API details in MyAryaka Complete the procedure described in this section to configure user and group API details in MyAryaka. You must provide the identifiers that you obtained in the previous procedure. To configure user and group API details in MyAryaka If it is not already open, navigate to the < IdPname > page for this Entra instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Entra tile in the Configured Identity Providers section. The < IdPname > page appears. Click  Edit  in the User and Group API Details pane. The User and Group API Details page appears in edit mode. Paste or enter the Application ID that was obtained from Microsoft Entra (step 3 in the previous procedure) into the Client ID field. Paste or enter the Value that was obtained from Microsoft Entra (step 3 in the previous procedure) into the Client Secret field. Paste or enter the Tenant ID that was obtained from Microsoft Entra (step 3 in the previous procedure) into the Tenant ID field. Accept the default 86400 seconds (24 hours) or enter a different synchronization interval (in seconds) in the Sync Period field. This is the amount of time that passes before MyAryaka obtains user and user group information from Microsoft Entra. (Conditional) Aryaka Identity Management currently supports up to 100 user groups for an organization. If your organization’s total group count is greater than 100, in the Groups section, enter group names in the  Filter Groups With Exact Match  field or enter partial group names in the  Filter Groups Start With  field to specify up to 100 groups that you want to configure for user identification. Click  View Filtered Groups  to view included user groups based on your filter criteria. Note:  If needed, you can still configure all IdP users in step 8. In the Users section, select one of the following toggles to specify which users to pull from the IdP: All Organization Users—Regardless of group configuration (specified in step 7), all users are pulled from the IdP and can be used for policy configuration. This option is selected by default. Users from Select Groups—Only users from the configured groups (specified in step 7) are pulled from the IdP. Click  Submit . A message confirms the configuration updates and your entries appear in the read-only User and Group API Details pane on the < IdPname > page. Map users to the Aryaka Identity Management application in Microsoft Entra Complete the procedure described in this section to assign users stored in Microsoft Entra to the new application you created for Aryaka Identity Management. To map users to Aryaka Identity Management in Microsoft Entra Log in to the Microsoft Entra admin center as an administrator. Click  Applications  >  Enterprise Applications  in the left navigation pane. The Enterprise Applications | All Applications page appears. In the Applications table, click the application name that you created in step 4a of the Configure SAML in Microsoft Entra procedure (we used the example of  Aryaka Pilot ). The selected application's Overview page appears. In the Getting Started section, click  Assign Users and groups . The <appName> | Users and Groups page appears with the currently assigned users and groups listed in the table. Click  Add user/group  above the table. The Add Assignment page appears. Click the  link  in the Users or Groups sections as appropriate. The Users or Groups page appears. Click the  checkbox  next to one or more users or groups that you want to assign to the selected application, then click  Select . The Add Assignment page appears with a count of users and groups selected. Click  Assign . The selected users or groups are assigned to the application and are synchronized between Microsoft Entra and MyAryaka when the next sync operation occurs (by default, it runs automatically every 24 hours). The Aryaka Identity Management >  IdPname  page includes a Last Successful Sync pane, which displays the timestamp of the last synchronization and the option to manually run the sync operation. Verify the integration in MyAryaka  Complete the procedure described in this section to verify your Entra integration in MyAryaka. After completing the configuration, you can view the total number of users and user groups in MyAryaka. To verify the Microsoft Entra integration If it is not already open, navigate to the < IdPname > page for this Entra instance: Log in to MyAryaka. The Home page appears. Click  Global Settings  in the left navigation pane. The Global Settings page appears and displays a series of tiles. Click  Manage  in the Identity Management tile. The Aryaka Identity Management page appears. Click  Manage  on the Enterprise’s Entra tile in the Configured Identity Providers section. The < IdPname > page appears and displays the following: Sync Status tile—Displays the date and time of the last successful synchronization between Aryaka Identity Management and Entra. Pre-configuration Steps for SAML—Displays read-only fields that were used to configure SAML in Entra. Entra SAML Details pane—Allows you to modify and test the current Entra configuration. User and Group API Details pane—Allows you to modify the API used to query your users and user groups.  (Optional) Click  Resync  in the Sync Status summary tile to manually run the sync operation between Entra and MyAryaka. The Last Successful Sync, Users, and User Group tiles are updated. (Optional) Click  Test IdP Configuration  in the Entra SAML Details pane to determine if Aryaka Identity Management can query Entra. A pop-up message indicates whether the test succeeds or fails. (Optional) Click  Test Authorization  in the User and Group API Details pane to verify authorization. A pop-up message indicates whether the test succeeds or fails. In this topic