Skip to main content
This guide walks you through registering Planasonix as an enterprise application in Microsoft Entra ID (formerly Azure AD) using SAML-based single sign-on. You need Cloud Application Administrator or Application Administrator (or a custom role that can manage enterprise apps) plus organization admin in Planasonix.
SSO is an Enterprise feature. Sign-in is SP-initiated: users start at Planasonix, then Entra ID, then return to the ACS. Entra ID labels change over time—if a step does not match, search for Enterprise applications and Single sign-on in the Microsoft Entra admin center. See SSO for the overall flow.

Values you copy from Planasonix

From Settings → SSO in Planasonix, copy:
  • Identifier (Entity ID) — Azure calls this Identifier in basic SAML configuration.
  • Reply URL (Assertion Consumer Service URL) — Azure calls this Reply URL.

Create and configure the enterprise application

1

Create the enterprise application

In Microsoft Entra admin center, go to Identity → Applications → Enterprise applications → New application → Create your own application. Name it (for example, Planasonix), choose Integrate any other application you don’t find in the gallery, and create the app.
2

Enable SAML single sign-on

Open the new application → Single sign-on → select SAML.
3

Set Identifier and Reply URL

Under Basic SAML Configuration, click Edit:
  • Identifier (Entity ID): paste the Planasonix Entity ID exactly. If Azure allows multiple values, keep a single entry unless your Planasonix admin gives you alternates.
  • Reply URL (Assertion Consumer Service URL): paste the Planasonix ACS URL exactly.
Save the configuration.
4

Download or copy IdP metadata

In the SAML Certificates section, download Federation Metadata XML or copy Login URL, Azure AD Identifier, and the Signing Certificate for manual entry in Planasonix.

Identifier and reply URL: trailing slashes

Azure AD compares Identifier and Reply URL strings literally. A trailing slash on the Planasonix Entity ID or ACS URL must match character-for-character in Entra ID.
A common failure is copying https://…/acs into Azure while Planasonix shows https://…/acs/ (or the reverse). The mismatch produces generic SAML errors in the browser. Copy from Planasonix without editing.

User and group assignment

Assign users or groups under Users and groups so they can complete SSO. Then upload the Federation Metadata XML (or paste Login URL, identifier, and signing certificate) into Planasonix Settings → SSO.
Test from the Planasonix sign-in page (SP-initiated). App-tile / IdP-initiated launch into Planasonix is not supported at launch.

SSO overview

ACS, Entity ID, and SP-initiated flow.

Session policy

Session length after Entra ID login.