Use this setup when users will sign in to Ziflow by initiating login from Microsoft's side rather than from Ziflow directly, for example, from https://myapps.microsoft.com, from the Microsoft Entra admin portal (Enterprise applications > Test this application), or any other Microsoft-hosted launch point.
Supported IdP-initiated configuration
Ziflow supports IdP-initiated SSO from Microsoft Entra when configured as follows.
1. Create a non-marketplace app
In Microsoft Entra, create a new non-gallery application
Do not use the Ziflow marketplace app
2. Configure SAML in Entra
Go to Single sign-on → SAML and set:
-
Identifier (Entity ID)
Your Unique ID, your tenant ID. To find yours, see Find your tenant ID.urn:auth0:ziflow-production:<UNIQUE_ID> -
Reply URL (ACS URL)
The Callback URL should match the URL shown in your Ziflow SSO tab and include the ?connection=... parameter. -
Sign-on URL
Leave this field empty
Setting a Sign-on URL will cause MyApps SSO to fail.
3. Complete SSO setup in Ziflow
In Ziflow → Account settings → Single Sign-On:
Type: SAML 2.0
Sign-In URL: Microsoft Login URL from Entra
X.509 Certificate: Entra Base64 certificate
Sign-Out URL: Microsoft Logout URL
Activate SSO
4. Assign users and test
Assign users or groups to the app in Entra
Users must launch Ziflow from Microsoft's side (MyApps, the Entra admin portal, or another IdP-initiated entry point) — not by navigating to Ziflow's login page directly first.
Common issue
If IdP-initiated login fails with errors such as:
“Required request parameter
codeis not present”“InResponseTo does not match”
“Connection is not enabled”
Check that Sign-on URL is not set in Entra.
Summary
For Ziflow SSO via Microsoft IdP-initiated login:
Use a non-marketplace Entra app
Configure Entity ID + Reply URL only
Do not set a Sign-on URL
Launch exclusively from Microsoft's side (MyApps, Entra admin portal, etc.) — not from Ziflow's own login page
Related to
Comments
0 comments
Please sign in to leave a comment.