# Azure Active Directory single sign-on (SSO) integration

In this tutorial, you'll learn how to integrate GetAccept with Azure Active Directory (Azure AD).

April 22, 2026

## Introduction

**Requirements:**

You'll need admin access to the GetAccept entity and your Microsoft Entra ID environment to set up SSO.

**When you integrate GetAccept with Microsoft Entra ID, you can:**

- Control who has access to GetAccept from your Active Directory.
- Enable users to be automatically signed in to GetAccept with their Microsoft account belonging to the Active Directory.
- Manage your accounts in one central location - the [Microsoft Entra ID portal](https://portal.azure.com/).

**Before setting up the integration it is good to understand:**

- Each GetAccept entity requires a unique Enterprise application in your Microsoft Entra ID environment. A GetAccept entity can only communicate with one application at a time.
- The login page [app.getaccept.com](https://app.getaccept.com/) is not supported for SSO, additional domain name configuration is required, read more about it in **[Step 10](https://help.getaccept.com/en/articles/3325391-azure-active-directory-single-sign-on-sso-integration#h_5716eb7b2e)**.
- To short-link directly to the SSO login, you can either use the unique SAML login URL presented in the **SAML Authorization** modal `https://app.getaccept.com/auth/saml/{entityId}/sso`, or the Enterprise application you've created for the [Apps Dashboard](https://myapplications.microsoft.com/#optIn) also known as My Apps.
- SSO is not supported with the use of subdomains, for example, [yourdomain.getaccept.com](https://yourdomain.getaccept.com/) because the Microsoft endpoint expects the SAML requests to come from [app.getaccept.com](https://app.getaccept.com/).

For SCIM Provisioning with Microsoft Entra ID, please read this [help article](https://help.getaccept.com/en/articles/3334384-automatic-user-provisioning-in-azure-ad-using-scim).

## How To Setup SAML

### Step 1: Adding GetAccept to your Enterprise applications

1. Sign in to the [Microsoft Entra ID portal](https://portal.azure.com/) using either a work or school account or a personal Microsoft account.
2. On the left navigation panel, select the service **Microsoft Entra ID**.
3. Select **Enterprise applications** and click **New application** at the top.
4. Click **Create your own application** at the top.
5. In the field "What's the name of your app?", enter **GetAccept**, or **GetAccept [Entity Name]** if you have multiple entities it's easier to keep track of them in your **Enterprise applications** list.
6. Select the option **Integrate any other application you don't find in the gallery (Non-gallery)** and click **Create**.

### Step 2: Prepare GetAccept SAML Configuration

Navigate to the SAML configuration in GetAccept.

1. Log in to [GetAccept](https://app.getaccept.com/).
2. Go to **Settings**.
3. Select **Integrations**.
4. Look for **Provisioning and SSO**.
5. Click the **Settings** button on the **SAML Authentication** connector.

_Make sure that you are logged in to GetAccept using **app.getaccept.com** and not a subdomain, for example, companyx.getaccept.com_

### Step 3: Configure Entra ID SSO

Follow these steps to enable SAML in the [Microsoft Entra ID portal](https://portal.azure.com/).

1. Go to **Enterprise applications** and select the **"GetAccept"** application you've created.
2. Find the **Manage** section and select **Single sign-on**.
3. On the **Select a single sign-on method** page, select **SAML**.
4. Click **Edit** (pencil icon) on **Basic SAML Configuration** to edit the settings.

5. Copy and paste the values from the **SAML Authentication** modal in GetAccept, the one you opened in **[Step 2](https://help.getaccept.com/en/articles/3325391-azure-active-directory-single-sign-on-sso-integration#enable-getaccept-sso)**, and follow the mapping below.

6. Click **Save** at the top and choose to validate later.

### Step 4: Configure GetAccept SSO

**Important note:** Before connecting SAML in GetAccept, we recommend opening a new [app.getaccept.com](https://app.getaccept.com/) session in incognito mode. You can use that tab to test the connection at the end of this guide, that way you can easily disconnect the SAML connector if you run into any error codes when testing.

### Step 5: Create User Roles and Assign Users

The next step is also a preparation for the SCIM Provisioning setup.

1. In the [Microsoft Entra ID portal](https://portal.azure.com/), go to **Enterprise applications**, and select the **"GetAccept"** application you've created in previous steps.
2. Look for the **Manage** section on the left menu and select **Users and groups**.
3. Click **Application Registration**.
4. Now it's time to create or modify your current **appRoles** of the application you've created. You're going to ensure that you have 3 **appRoles** in the application, one for **administrators, managers,** and **users.** Here are the roles you need in the application:

- **Display name:** User  
      **Description:** Users can create, send, and view documents  
      **Allowed member types:** Users/Groups  
      **Value:** user  
    
    - **Display name:** Manager  
      **Description:** Managers can manage teams and their documents  
      **Allowed member types:** Users/Groups  
      **Value:** manager  
    
    - **Display name:** Administrator  
      **Description:** Administrators can manage entity settings and users  
      **Allowed member types:** Users/Groups  
      **Value:** admin

5. Once the roles are created, you can go back to **Users and groups**, add yourself with the appRole Administrator, and proceed with the guide.

### Step 6: Validate and Save

Verify that your Microsoft Entra ID Active Directory users match the GetAccept user's email address. You can modify additional Attributes & Claims if needed; we recommend turning to Microsoft help articles; by default, GetAccept uses the `user.mail` as the identifier for SSO.

1. To test and validate the SAML configuration, go to the application you've created, look for **Manage** on the left side, and select **Single sign-on**.
2. Click the **Test** button at the bottom of the page.
3. A new modal will appear on the right-hand side, click the **Test** **sign in** button to initiate the test on the current user.

4. Another tab should open in a few seconds, login with your Microsoft account and verify that you're logged in as the correct user on the correct entity at GetAccept in your upper right corner. If everything is working, then you're done with the SAML configuration for now **🎉**

5. If you are running into an error, check the error message in the "Resolving errors" dialogue and take a closer look at the Troubleshoot section below. We also recommend double-checking the guide in case a step was missed or if an error was made.

### Step 7: Add the GetAccept Logo

We recommend that you enable the application to all users and also upload the GetAccept logo.

1. Download the GetAccept logo below by right-clicking and saving the logo.
2. In the app's overview page, find the **Manage** section and select **Properties**.
3. Upload the PNG file under Logo.
4. Click **Save** at the top.

### Step 8: Test SSO

We also recommend testing and verifying that your SSO works with the incognito session mentioned in **[Step 4](https://help.getaccept.com/en/articles/3325391-azure-active-directory-single-sign-on-sso-integration#configure-getaccept-sso)**, that way you can remove the **SAML Authentication** in GetAccept if you run into any errors, also read the **Troubleshooting** section below if you run into any error messages.

### Step 9: [Optional] Redirect to a specific page after SSO

If you want to redirect a user to a specific page or document behind a secure login you can use a custom "go" parameter in the SSO URL. This is powerful if you use an external system to generate the document and receive the Send-out URL or document URL for editing before sending it out.

Example of how to redirect and open a document for editing before sending:

```  
https://app.getaccept.com/auth/saml/abcd1234/sso?go=/document/edit/xyz1234abc
```

### Step 10: [Optional] Sign in with SSO on app.getaccept.com

You can set up domain name-based authorization on the login page [app.getaccept.com](https://app.getaccept.com/). This will act as a bridge between the login page, your entity, and its SAML configuration. If you want to utilize [app.getaccept.com](https://app.getaccept.com/) as the main login page for your users, you can add a unique domain name to your entity.

## Troubleshooting

### Authentication Error / WindowsIntegrated

**For the error AADSTS750:**

```
AADSTS750: Authentication method “WindowsIntegrated, MultiFactor” by which the user authenticated with the service doesn’t match requested authentication method “Password, ProtectedTransport”
```

**or AADSTS75011**:

```
AADSTS75011: Authentication method “X509, MultiFactor” by which the user authenticated with the service doesn’t match requested authentication method “Password, ProtectedTransport”. Contact GetAccept application owner.
```

We have seen that omitting `RequestedAuthnContext` value in the request is a workable solution. You can change this by specifying the following attribute in your GetAccept SAML configuration under Optional Attributes (JSON):

```json
{
    "authnContextClassRef" : false
}
```

### Signature Validation Failed

**For the error:**

```
"Signature validation failed. SAML Response rejected"
```

This means that the signature validation process failed. In this case, the X.509 certificate added to the GetAccept SAML connector is incorrect.

### Application not found in directory

**For the error AADSTS700016:**

```
AADSTS700016: Application with identifier 'https://companyx.getaccept.com/auth/saml/xyz123/metadata.xml' was not found in the directory 'xxxx'
```

This means that the Microsoft Entra ID application has been set up using the incorrect URL:s to the application, note that it shouldn't be set up while logged in to GetAccept using a subdomain. Make sure that you are logged into [https://app.getaccept.com](https://app.getaccept.com/), go to Settings, Integrations, Provisioning and SSO, and SAML Authentication, and make sure to copy the correct values to the Azure application configuration.
