4.2.3 Configuring Single Sign-On in Microsoft Entra ID

To configure SSO for NFON X powered by Telekom cloud telephony in Microsoft Entra ID: 

  1. Sign in to the Microsoft Entra admin center as a Cloud Application Administrator

  2. Browse to Entra ID > Enterprise apps > All applications

  3. Select New Application.

4. Select Create your own application. 

5. Name your application.

6. Click Create.

7. In the Manage section of the menu on the left, select Single sign-on to open the Single sign-on pane for editing. 

8. Select SAML to open the SSO configuration page.

9. Edit the Basic SAML Configuration on the SAML-based sign-on page.

10. Enter the Identifier (Entity ID) and Reply URL (Assertion Consumer Service URL) from the NFON X powered by Telekom Single Sign-On configuration page.

11. Enter the Logout URL by using the Reply URL (Assertion Consumer Service URL).
The Logout URL ensures that after the user logs out from an NFON X powered by Telekom application, they will first log out from Microsoft Entra and then be redirected back to the NFON X powered by Telekom application login screen.

12. Keep the standard settings for Attribute & Claims.

13. Download the Certificate (Base64) version of the SAML certificates to your local machine.

14. You can open the downloaded file (.cer) with a text editor of your choice to get the certificate in a PEM format – including the BEGIN/END CERTIFICATE markup. 

15. You will find the Login URL, Microsoft Entra Identifier and the Logout URL below the SAML certificates step.
Please note that you will need these three values and the certificate later on.