Azure AD SSO configuration example

Before configuring your Sitecore Content Hub to authenticate using the Azure AD single sign-on (SSO), you must create and configure an Azure application registration.

To do this, you must perform the following steps:

  1. Create your application registration.

  2. Configure the token.

  3. Expose your API.


Refer to the official Microsoft Azure documentation for the correct procedures.

When exposing your API, retrieve the following information to use when configuring SSO in Content Hub:

  • Application ID URI, for example api://111bb1a1-bb1b-1111-11bb-b11b111b111b.

  • Federation metadata document, for example

  • EntityID, for example

With these values, you can configure the authentication setting using the following JSON schema:


   "ExternalAuthenticationProviders": {
      "global_username_claim_type": "",
      "global_email_claim_type": "",
      "saml": [
          "metadata_location": "Federation metadata document value",
          "sp_entity_id": "Application ID URI value",
          "idp_entity_id": "EntityID",
          "provider_name": "AzureAD SSO",
          "messages": {
            "signIn": "AzureAD SSO"
          "authentication_mode": "Passive",
          "module_path": "AuthServices",
          "is_enabled": true

Do you have some feedback for us?

If you have suggestions for improving this article,