# Microsoft Entra ID setup

> Learn how to set up Microsoft Entra ID (formerly Azure Active Directory) as an identity provider for Sketch with the help of our step-by-step guides and video tutorials.

**URL:** https://www.sketch.com/docs/getting-started/single-sign-on/setting-up-saml-sso/setup-identity-provider/azure-active-directory/ | **Last updated:** 2026-01-23

---
1. Log in to Microsoft Entra ID as an Admin.
1. Go to the **Microsoft Entra ID** page.
   ![An image showing where the link to Microsoft Entra ID is in the sidebar](https://cdn.sketch.com/docs/sso/azure-2_microsoft-Entra-page.png)
1. Click on **Enterprise applications**.
   ![An image showing where the Enterprise application tab is in the sidebar](https://cdn.sketch.com/docs/sso/azure-3_enterprise-applications.png)
1. Click on **New application**.
   ![An image showing the new application button in Microsoft Entra ID](https://cdn.sketch.com/docs/sso/azure-4_new-application.png)
1. In the **Browse Microsoft Entra Gallery** page, type `sketch` in the search box.
   ![An image showing the search results for the Microsoft Entra gallery](https://cdn.sketch.com/docs/sso/azure-5_browse-msentra-gallery.png)
1. Select the **Sketch** tile from the results panel and then add the app. Give it a name, for example `Sketch` and click **Create**. Wait a few seconds while the app is added to your tenant.
   ![An image showing app options](https://cdn.sketch.com/docs/sso/azure-6_create-app.png)
1. Click on **Single sign-on**.
   ![An image showing the single sign-on option in Microsoft Entra](https://cdn.sketch.com/docs/sso/azure-7_click-single-sign-on.png)
1. Select the **SAML** tile.
   ![An image showing the SAML button](https://cdn.sketch.com/docs/sso/azure-8_select-saml-tile.png)
1. Complete the **Basic SAML Configuration** section using the following information from the Single Sign-On tab of the People & Settings page in the Sketch web app:
    - **Identifier (Entity ID)**: `Your Workspace’s Entity ID`
    - **Reply URL (Assertion Consumer Service URL)**: `Your Workspace’s ACS URL`
    - **Sign-on URL**: `https://www.sketch.com`

    **Note**: Make sure that there are no spaces at the end of these fields — if there are, the SSO process will fail.
    Next, complete the **Attributes & Claims** section. Make sure you don’t use any namespace.
    ![An image showing the Basic SAML configuration and the Attribute & Claims configuration section](https://cdn.sketch.com/docs/sso/azure-step-1-v4@2x.jpg)
*Examples of the Basic SAML Configuration and the Attributes & Claims sections. The entered values will be different for every account*
    The values in the right column will be specific to your organisation — make sure that you add the right information.

     **Note**: If you are using Safari, you might have trouble typing in the text field. We recommend trying another browser.
1. Download the **Federation Metadata XML** file from the link in the **SAML Certificates** section — you’ll need it when setting up SAML SSO in Sketch.
    ![An image showing the link to download the federation metadata xml](https://cdn.sketch.com/docs/sso/azure-10_metadata.png)
1. Head to **Users and groups** to give access to Sketch to relevant users.
    ![An image showing the users and groups section in Microsoft Entra](https://cdn.sketch.com/docs/sso/azure-11_users-and-groups.png)
1. Head to [How to finish setting up SAML SSO in your Workspace](/docs/getting-started/single-sign-on/setting-up-saml-sso/finish-setting-saml-sso/) to finish the SAML SSO process in Sketch.