Enabling single sign-on via Microsoft Entra ID

Requirements

  • Advanced Authentication and Security

Set up single sign-on (SAML) for Robin with the pre-configured SAML app in Microsoft Entra ID (formerly Azure Active Directory). First add the Robin app in Entra ID, then import its metadata into Robin.

Add the Robin app in Microsoft Entra ID

  1. In Microsoft Entra ID, go to Enterprise Applications > New Application.
  2. Search for Robin, select the Robin app by Robin Powered, then select Create.
  3. In the Robin app, select Single sign-on.
  4. In the SAML Certificates section, select Download next to Federation Metadata XML. You import this file into Robin in the next section.

Turn on SAML in Robin

  1. As a Robin admin, open the Robin web dashboard and go to Manage > Security. You can also go to Manage > Integrations and select Manage Sign-In Options.
  2. In the SAML 2.0 card, select Add. The SAML configuration form opens.
  3. Select Import IDP Metadata and import the Federation Metadata XML file you downloaded.
  4. Select Advanced Options.
  5. Under Auth Context, uncheck every box. Robin then does not ask for a sign-in method, and Microsoft Entra ID uses any method.
  6. Uncheck Encrypt Assertion. When it is checked, Robin asks for an encrypted NameID, and Microsoft Entra ID does not accept that format.
  7. Select Save Configuration.

If the pre-configured app does not work for you, connect Microsoft Entra ID as a custom integration. Follow the steps in Enabling single sign-on via SAML 2.0.

Fix common sign-in errors

If sign-in fails, Microsoft shows an error code. Find the code below.

Error Fix
AADSTS750161: "Allowed SAML authentication request's NameIDPolicy formats are..." Robin asked for an encrypted NameID, which Microsoft Entra ID does not accept. In Robin, uncheck Encrypt Assertion under Advanced Options.
AADSTS75011: "Authentication method used doesn't match the requested authentication method" The user signed in with a method that Robin did not ask for, such as Windows Hello, a passkey or multifactor authentication. In Robin, uncheck every box under Auth Context.

Articles in this section

Was this article helpful?
1 out of 6 found this helpful
Share