This article explains how to configure single sign-on (SSO) for Cye Cloud Posture Solution with Microsoft Azure Entra ID as your SAML 2.0 identity provider.
Overview
Cye Cloud Posture Solution supports a wide variety of SAML 2.0 Identity Providers (IdPs), so your team can sign in to the console with the credentials it already uses. For SAML 2.0, the console uses AWS Cognito, which does not support IdP-initiated flows: users always start from the SSO login page at console.solvo.cloud/loginsso, not from the Microsoft My Apps portal.
Create & Configure the Enterprise App: Add a non-gallery enterprise application in Azure Entra ID, set SAML as the single sign-on method, and enter the console's entity ID, reply URL, and sign-on URL.
Map Claims & Assign Users: Keep the default user attributes and claims so user details populate automatically, then assign the users or groups who may sign in.
Connect & Test: Paste the App Federation Metadata Url into the console's SSO settings, then sign in from the SSO login page to confirm the redirect to Azure Entra ID and back.
1. Create a custom enterprise application
1. Create a custom enterprise application
The enterprise application represents the console inside your Azure Entra ID tenant.
In the Azure Entra ID admin center, go to Enterprise applications > New application.
Select Create your own application.
Choose Integrate any other application you don't find in the gallery (Non-gallery).
Give the application a descriptive name and click Create.
2. Configure SAML single sign-on
2. Configure SAML single sign-on
In your new enterprise application, go to Single sign-on.
Select SAML as the SSO method. The SAML-based Sign-on configuration page opens.
3. Configure basic SAML settings
3. Configure basic SAML settings
These values tell Azure Entra ID where to send SAML responses.
In the Basic SAML Configuration section, click Edit.
Enter the following values:
Identifier (Entity ID):
urn:amazon:cognito:sp:us-east-1_U0FR6cmpeReply URL (Assertion Consumer Service URL):
https://signin.solvo.cloud/saml2/idpresponseSign on URL:
https://console.solvo.cloud/loginsso
4. Review user attributes and claims
4. Review user attributes and claims
The default claims populate user attributes in Cye Cloud Posture Solution automatically during SSO, so no changes are usually needed.
Go to the User Attributes & Claims section.
Confirm the claims match the defaults:
Required claim: Unique User Identifier (Name ID), typically
user.userprincipalname.Additional claims:
Claim name | Source attribute |
|
|
|
|
|
|
|
|
5. Copy the metadata URL
5. Copy the metadata URL
The console reads all SAML configuration details from this URL.
In the SAML Signing Certificate section, locate the App Federation Metadata Url.
Copy the URL. You paste it into the console in step 7.
6. Assign users or groups
6. Assign users or groups
Only assigned users can sign in through the enterprise application.
In your enterprise application, go to Users and groups.
Click Add user/group.
Select the users or security groups who need access.
7. Set up the SSO integration in the console
7. Set up the SSO integration in the console
Log in to the console, open the settings page, and click Add SSO integration.
In the SSO settings dialog, paste the URL you copied in step 5 and click Done.
8. Test the configuration
8. Test the configuration
Log out of the console.
Enter your email address and click Login.
You are redirected to Azure Entra ID to authenticate.
After successful authentication, you are redirected back to the console and logged in automatically.
External users
External users
A user who signs in through an SSO integration is an external user. The users management page shows these users with the external label.
Wrap-up / Next Steps
Wrap-up / Next Steps
Sign in with SSO: Start from the SSO login page. Signing in from the Microsoft My Apps portal (IdP-initiated flow) is not supported.
Review SSO users: Open the users management page to see which users signed in through Azure Entra ID.
Use a different IdP: For Okta, see Setting Up Okta SSO.




