> ## Documentation Index
> Fetch the complete documentation index at: https://docs.abbyy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Azure AD as a SAML 2.0 External Identity Provider

> Configure Azure Active Directory (Azure AD) as a SAML 2.0 External Identity Provider for ABBYY Vantage: register the app, create the Redirect URI, set up SSO.

## Prerequisites

* Ensure that you have a Vantage tenant identifier before configuring identities. To get a tenant identifier, click **Configuration** in ABBYY Vantage. The identifier is on the **General** tab.
* Create a Redirect URI to receive the authentication responses. The URI is: \
  `https://<your-vantage-url>/auth2/Saml2/Acs`
* Create an application registration (see the instructions [below](#creating-the-application)). Registering your application establishes a trust relationship between your application and the External Identity Provider.

### Creating the application

To create the application, follow these steps:

<Steps>
  <Step title="Open the Azure Portal">
    Go to [Azure Portal](https://portal.azure.com/) and sign in. In the pane on the left, select **Azure Active Directory**.
  </Step>

  <Step title="Open App registrations">
    In the pane on the right, select **App registrations** and click **New registration**.

    <Frame>
      <img src="https://mintcdn.com/abbyy/jZX7kaKQgdxaDiIT/images/vantage/tenant-admin/sysadmin_identityprovider_azuread_1.png?fit=max&auto=format&n=jZX7kaKQgdxaDiIT&q=85&s=516dc38daf0522bc12250b5f5a8cc010" alt="Azure AD App registrations pane with the New registration button highlighted" width="1880" height="840" data-path="images/vantage/tenant-admin/sysadmin_identityprovider_azuread_1.png" />
    </Frame>
  </Step>

  <Step title="Fill in the registration form">
    Specify the following:

    * **Name** — a name for the application.
    * **Supported account types** — select **Accounts in this organizational directory only**.
    * **Redirect URI** — for each Vantage URL that should authenticate using this account, enter `https://<your-vantage-url>/auth2/Saml2/Acs`.

    <Frame>
      <img src="https://mintcdn.com/abbyy/jZX7kaKQgdxaDiIT/images/vantage/tenant-admin/sysadmin_identityprovider_azuread_5.png?fit=max&auto=format&n=jZX7kaKQgdxaDiIT&q=85&s=555f69b01ed5eb5abd3683cb079c4c50" alt="Azure AD application registration form with name, supported account types, and SAML redirect URI fields" style={{ width:"79%" }} width="624" height="557" data-path="images/vantage/tenant-admin/sysadmin_identityprovider_azuread_5.png" />
    </Frame>
  </Step>

  <Step title="Register the application">
    Click **Register**.
  </Step>
</Steps>

Next, set up Azure Active Directory to be used as an External Identity Provider.

## Set up Azure Active Directory

To set up Azure Active Directory, follow these steps:

<Steps>
  <Step title="Set the Application ID URI">
    In the **Expose an API** tab, set the **Application ID URI**. Due to [Microsoft Entra identifier URI restrictions](https://learn.microsoft.com/en-us/entra/identity-platform/identifier-uri-restrictions), use the format `api://<appId>`, where `appId` is the Application ID from the app registration (for example, `api://cccc3333-dddd-4444-eeee-5555ffff6666`). Copy this value — you'll need it when configuring the External Identity Provider in Vantage.
  </Step>

  <Step title="Copy the federation metadata URL">
    Select the **Overview** tab and click **Endpoints**. Copy the value of the **Federation metadata document** field.
  </Step>
</Steps>

## Next steps

Once Azure AD is configured, connect it to your Vantage tenant. You'll need the URL to the **Federation metadata document** you copied in the Set up section (step 2).

For the Vantage-side setup, see [Setting up an External Identity Provider for a tenant](/vantage/documentation/tenant-admin/tenant-management/configuring-tenant).

## Related topics

<CardGroup cols={2}>
  <Card title="Configuring a SAML 2.0 External Identity Provider" icon="shield-halved" href="/vantage/documentation/tenant-admin/tenant-management/saml-2-0">
    Overview of SAML 2.0 setup for AD FS or Azure AD
  </Card>

  <Card title="Active Directory as a SAML 2.0 External Identity Provider" icon="shield-halved" href="/vantage/documentation/tenant-admin/tenant-management/saml-2-0-active-directory">
    Configure on-premises AD FS instead of Azure AD
  </Card>

  <Card title="Setting up an External Identity Provider for a tenant" icon="sliders" href="/vantage/documentation/tenant-admin/tenant-management/configuring-tenant">
    Connect Azure AD to your Vantage tenant
  </Card>

  <Card title="Testing external authentication" icon="vial" href="/vantage/documentation/tenant-admin/tenant-management/testing-external-auth">
    Verify the External Identity Provider before users sign in
  </Card>
</CardGroup>
