Integrations

/

Microsoft Entra ID SAML2 SSO: Secure Single Sign-On with Flexopus

With the Microsoft Entra ID SAML2-SSO integration, your employees can log in to Flexopus with just one click – without any separate passwords. Flexopus uses the proven SAML2 protocol to seamlessly integrate into your existing Microsoft identity infrastructure.

No items found.
No items found.

What is the Microsoft Entra ID SAML2 SSO integration?

Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management solution. Companies can integrate Flexopus as a trusted application into Entra ID via the SAML2 protocol (Security Assertion Markup Language).

Technically speaking, Microsoft Entra ID acts as an Identity Provider (IdP): It issues a signed authentication request upon login and securely transmits the user information – such as name, email address, department and job title – to Flexopus via SAML2 assertion. Flexopus processes this data and grants the user access without requiring a separate password.

Optionally, the integration can be combined with SCIM user provisioning to automatically create, update, or deactivate user accounts.

What is the purpose of integration?

SAML2 SSO integration simplifies the daily work of your employees and simultaneously relieves the burden on IT administration. Typical use cases:

  • Single sign-on: Users who are already logged into Microsoft 365 can access Flexopus directly – without having to enter their password again.
  • Centralized access control: Entra ID allows you to precisely control which users and groups are allowed to log in to Flexopus.
  • Automatic user registration: New employees are automatically created in Flexopus upon their first login – no manual account creation is required.
  • Synchronization of user attributes: Fields such as name, email, department and job title are kept up to date with each login.
  • Optional group synchronization: Groups from Entra ID can be passed to Flexopus via the memberOf attribute to automatically assign access rights.

How easy is the integration?

The setup is completed in just a few steps directly in the Microsoft Entra Admin Center and in the Flexopus settings. You create an enterprise application in Entra ID, configure the SAML2 attribute assignments, and store the metadata URL in Flexopus. You can then test the SSO login immediately.

You can find a complete step-by-step setup guide in our 

Help Center

What are the advantages of integration?

  • Convenient login: A single Microsoft account is all you need to access Flexopus – no additional passwords, no password resets.
  • Central user management: Changes in Entra ID (e.g. Name changes, department changes) are automatically transferred to Flexopus.
  • Increased security: Microsoft 2FA settings also apply to Flexopus login – without any additional configuration effort.
  • Reduced administrative effort: New employees are automatically created upon their first login; departing employees immediately lose access upon deactivation in Entra ID.
  • Flexible security management: Password login can optionally be completely disabled to enforce SSO as the only login method.
  • Included free of charge: SAML2 SSO integration is included in the Flexopus subscription – at no extra cost.
  • Compatible with SCIM: For even more automation, SSO can be combined with SCIM provisioning.
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

What user data is transferred from Entra ID to Flexopus?

At each login, Entra ID transmits the basic user attributes via SAML2 assertion: first name, last name, email address, and optionally department and job title. Only the data necessary for registration and user maintenance in Flexopus will be transferred.

What happens if an employee is deactivated or deleted in Entra ID?

If a user account in Entra ID is deactivated or deleted, the person in question can no longer log in to Flexopus, as the login is done via the Microsoft Identity Provider. Existing bookings remain unaffected and may need to be managed manually. For fully automatic deactivation, we recommend the additional use of SCIM integration.

Can I disable password login after setting up SSO?

Yes. After successfully configuring SAML2-SSO, you can disable email/password login or hide the login form in the Flexopus settings. This ensures that all users access Flexopus exclusively via Microsoft Entra ID. A secure admin access will be maintained for emergencies.

Does Microsoft two-factor authentication also apply to Flexopus?

Yes. Since authentication is handled entirely via Microsoft Entra ID, all security policies configured there – including two-factor authentication (2FA) – automatically apply to Flexopus login as well.

Can user groups from Entra ID also be synchronized?

Yes, groups from Entra ID can be transmitted to Flexopus at every login via the optional memberOf-SAML2 attribute. Flexopus then automatically assigns users to the appropriate groups. Please note that the memberOf attribute has a technically imposed upper limit on the number of transferable groups.