Set up Microsoft Entra ID as the Identity Provider Using SAML 2.0 - Administrator Guide - Cortex XSIAM - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide

This topic provides specific instructions for using Microsoft Entra ID (formerly Azure AD) to authenticate your Cortex XDR users. As Microsoft Entra ID is a third-party software, specific procedures, and screenshots may change without notice. We encourage you to also review the Microsoft Entra ID documentation.

To configure SAML SSO in Cortex XDR, you must be a user who can access the Cortex XDR tenant and have either the Account Admin or Instance Administrator role assigned.

The following video is a step-by-step guide configuring SSO for Microsoft Entra ID: Microsoft Entra ID SSO.

Within Microsoft Entra ID, assign users to security groups that match the user groups they will belong to in Cortex XDR. Users can be assigned to multiple Microsoft Entra ID groups and receive permissions associated with multiple user groups in Cortex XDR. Use an identifying word or phrase, such as Cortex XDR, within the group names. For example, Cortex XDR Analysts. This allows you to send only relevant group information to Cortex XDR, based on a filter you will set in the group attribute statement.

  1. In Cortex XDR go to SettingsConfigurationsAccess ManagementSingle Sign-On.

  2. By default, SSO is disabled in Cortex XDR.

  3. Expand the SSO Integration settings.

  4. Copy and save the values for Single Sign-On URL and Audience URI (SP Entity ID).

    Both values are needed to configure your IdP settings.

    Important

    When copying the Single Sign-On URL value, remove idp/saml and leave the trailing /.

    For example, if the Single Sign-On URL is https://clientname.panproduct.region.paloaltonetworks.com/idp/saml, just copy https://clientname.panproduct.region.paloaltonetworks.com/.

  5. You cannot save the enabled SSO Integration at this time, as it requires values from your IdP.

  1. From within Microsoft Entra ID, create a Cortex XDR application and Edit the Basic SAML Configuration.

    Azure-Basic-SAML-8.png
  2. Paste the Single sign-on URL and the Audience URI (SP Entity ID) that you copied from the Cortex XDR SSO settings. The Single sign-on URL from Cortex XDR should be pasted in the Reply URL and the Sign on URL fields. The Audience URI (SP Entity ID) value from Cortex XDR should be pasted in the Identifier (Entity ID) and Relay State fields. This allows users to log in to Cortex XDR directly from Microsoft Entra ID.

    azure-basic-saml.png
  3. In the SAML Certificates section, click Edit and verify that Microsoft Entra ID is configured to sign both the response and the assertion.

    Azure-Sign-Certificate-8.png
  4. To have Microsoft Entra ID send group membership for the user in the SAML token, you must + Add a group claim in the Attributes & Claims section. Send the Security groups, using the source attribute Group ID. Use the word or phrase you selected when configuring Microsoft Entra ID security groups (such as Cortex XDR) to create a filter. Customize the name of the group claim as memberOf.

    Azure-memberof-Group-8.png
  5. In addition to group membership, verify that there are also claims for:

    • Email address

    • First Name

    • Last Name

  1. In Microsoft Entra ID, from the Single sign-on page, in the Set up Cortex XDR Production section, copy the values for the Login URL and Microsoft Entra ID Identifier. You need these values to configure the SSO Integration in Cortex XDR.

    Azure-XSOAR-Settings-8.png
  2. Edit Attributes & Claims and copy the values in the Claim name column. The claim name is case sensitive. You need these values to configure the SSO Integration in Cortex XDR.

    Note

    The default attributes shown on the main single sign-on page in Microsoft Entra ID are not the values you need. You must click Edit next to Attributes and Claims to view and copy the actual values.

    Azure-claim-names-8.png

From the SAML Certificates section in Microsoft Entra ID, Download the Certificate (Base64). You need the contents of this file to configure the Cortex XDR SSO Integration.

Azure-download-certificate-8.png

The claim for the membership attribute that is sent to Cortex XDR uses the Object Id of the group. The Object Id is different from the Microsoft Entra ID security group name. You can find the Object Id for each of your Microsoft Entra ID security groups by navigating to Users and groups in Microsoft Entra ID, clicking on the group name, and viewing the Object id. Create a list of the group names and corresponding Object Ids for every Microsoft Entra ID security group you want to map to a Cortex XDR user group.

  1. In Cortex XDR go to SettingsConfigurationsAccess ManagementSingle Sign-On.

  2. By default, SSO is disabled in Cortex XDR.

  3. Expand the SSO Integration settings.

  4. Use the following table to complete the SSO Integration settings, based on the values you saved from Microsoft Entra ID.

    Microsoft Entra ID

    Cortex XDR Field

    Login URL

    IdP SSO URL

    Microsoft Entra ID Identifier

    IdP Issuer ID

    Contents of the downloaded certificate file.

    X.509 Certificate

  5. In the IdP Attributes Mapping section, enter the attribute claim names from Microsoft Entra ID. The names are case sensitive and must match exactly.

    Note

    The attribute claim name must exactly match the value sent by your IdP. In some cases, this may be the full attribute name/namespace, depending on the configuration of our IdP

    Azure-XSOAR-Attributes-8.png
  6. (Optional) Under Advanced Settings, select the checkboxes for ADFS and Compress encode URL (ADFS). In some circumstances, these fields may be required by your Microsoft Entra ID configuration.

  7. Save your settings.

  1. Select SettingsConfigurationsAccess ManagementUser Groups.

  2. Right-click a user group and select Edit Group.

  3. In the SAML Group Mapping field add the Microsoft Entra ID group(s) Object Ids that should be associated with this user group. Multiple Object Ids should be separated with a comma. The Microsoft Entra ID group Object Id must match the exact value sent in the token.

  4. Save your settings.

  5. Repeat for each user group.

  1. Go to the Cortex XDR tenant URL and Sign-In with SSO.

    Note

    When using SAML 2.0, users are required to authenticate by logging in directly at the tenant URL. They cannot log in via Cortex Gateway.

  2. After authentication to Microsoft Entra ID, you are redirected again to the Cortex XDR tenant.

  3. When logged in, validate that you have been assigned the proper roles.

    To view your role and any role assigned to a user group you are a member of, click your name in the bottom left-hand corner, and click About.