Configure SSO Between Routing Director and Microsoft Entra ID

Use the information in this topic to configure SAML SSO between Microsoft Entra ID and Routing Director.

Use this procedure to create and configure a Microsoft Entra ID Enterprise Application for Juniper Routing Director SAML authentication. Routing Director acts as the SAML Service Provider (SP), and Microsoft Entra ID acts as the Identity Provider (IdP).

Before You Begin

Obtain the following information from Routing Director:

  • Assertion Consumer Service (ACS) URL
  • Service Provider Entity ID
  • Planned Routing Director role names for RBAC mapping. To create the role names:
    1. Log in to Routing Director and navigate to Settings Menu > System Settings. The Organization Settings page is displayed.
    2. Click the Create Role (+) icon.
    3. On the Create Role page, configure the following:
      • Name — enter the name of your IdP user group. For example, SuperUser or Network Admin.
      • Role — select the required predefined role:
        • Super User
        • Network Admin. Access Control Profile is required when assigning the Network Admin role. Select one or more profiles that determine which resources the Network Admin can access.
    4. Click Create.

    The new mapping will then appear in the Roles table.

  • (Optional) Routing Director metadata file.

    To fetch the metadata, use the metadata API endpoint from Routing Director.

    Response will look like below and extract metadata field from JSON output.

    Extracted metadata will look similar to following XML content.

Proceed to configure the Microsoft Entra ID.

Create the Enterprise Application

  1. Sign in to the Microsoft Entra admin center.
  2. Navigate to Entra ID > Enterprise Applications.
  3. Select All applications.
  4. Click New application to create a new application for Routing Director.
  5. Select Create your own application.
  6. Enter a name for the application. For example, JRD Demo 2026.
    Create the application as a non-gallery application. Select Integrate any other application you don't find in the gallery (Non-gallery).
    Figure 1: Create application Microsoft Entra Admin Center interface showing navigation menu with options like Overview, Users, Groups, and Devices. Main section displays Browse Microsoft Entra App Gallery page with filters for Single Sign-On, User Account Management, Categories, and Risk Score. A pop-up window titled Create your own application shows a form for adding an app named JRD Demo 2026 with Non-gallery integration selected.
  7. Save the configuration.
  8. Verify that the application you created appears in the Enterprise Applications list.
    Figure 2: Enterprise applications list Microsoft Entra Admin Center interface showing the overview page for enterprise application JRD Demo 2026, with navigation menu, application details, and success notification confirming app addition.

Configure SAML Single Sign-On

Configure SAML based single sign-on.

  1. Open the newly created Enterprise Application, and click Single sign-on (see Figure 2). The Single sign-on page appears.

  2. Select SAML as the sign-on method on the Single Sign-on page.

    The SAML-based Sign-on page is displayed.

  3. Configure the following:

Basic SAML

Configure the basic SAML parameters using one of the following methods:
  • Configure Values Manually

    1. In the Basic SAML Configuration section on the SAML-based Sign-on page, click Edit.
    2. Click Add identifier to manually update the Microsoft Entra Identifier (Entity ID). Enter Routing Director Assertion Consumer Service (ACS) URL as the Identifier (Entity ID).
      Figure 3: Configure basic SAML parameters
      Basic SAML Configuration screen in Microsoft Entra for setting up SSO with fields for Identifier and Reply URL required for authentication.
    3. Click Add reply URL and enter Routing Director ACS URL as the Reply URL (Assertion Consumer Service URL).
    4. Save the configuration.
    5. Verify that all values match the Routing Director configuration. Go to Verify Basic SAML Configuration.
  • Import Routing Director Metadata

    1. Above the Basic SAML Configuration section, click Upload metadata file.

    2. Browse to the Routing Director metadata file that you saved in your local storage and upload it.
    3. Verify that the Identifier (Entity ID) and Reply URL are populated automatically.
      Figure 4: Configure Entity ID and Reply URL Configuration screen for SAML-based Single Sign-On in Microsoft Entra for JRD Demo 2026. Shows navigation panel and SAML settings.
    4. Save the configuration.
    5. Verify that all values match the Routing Director configuration.

Verify Basic SAML Configuration after the update. Ensure that the Service Provider Entity ID and ACS URL match the values configured in Routing Director.

SAML Signing Certificate

Configure the SAML certificate parameters:

  1. In the SAML Certificates section on the SAML-based Sign-on page, click Edit. The SAML Signing Certificate page is displayed.
  2. Click the Signing Option drop-down list and select Sign SAML response and assertion.
  3. Select the appropriate Signing Algorithm. The same algorithm must also be updated in the Routing Director configuration.
  4. Configure the Notification Email Address to receive alerts about certificate expiry.
    Figure 5: Configure signing option, algorithm, and notification e-mail Configuration interface for SAML-based single sign-on setup in an enterprise application, highlighting active SAML signing certificate details with expiration date 2/11/2029, signing option Sign SAML response and assertion, and algorithm SHA-256. A green notification confirms successful update of certificate notification email address.
  5. Save the configuration and verify the updates.

  6. Download the certificate in Base64 format. The certificate information must be updated in Routing Director.
    Figure 6: Download Certificate (Base64) Single sign-on configuration page in Azure Active Directory, showing SAML certificates section with details like token signing certificate, status, thumbprint, expiration, notification email, and download links for certificate and metadata.
  7. Note down the following information:
    • Microsoft Entra Identifier (Entity ID)
    • Signing Algorithm
    • Location of the Certificate (Base64) file.

    This information is required when configuring Routing Director as a SAML Service Provider.

Assign Users and Groups

  1. Click Users and groups from the left menu.
  2. Click Add user/group.
  3. Search for users and/or groups that require access to Routing Director select the required users and groups.
    Figure 7: Add users and groups User interface screenshot of a management portal showing a search for paragon testers with 1 result found. The result is a group named Paragon Testers with the domain juniper.net. Navigation menu includes options like audit logs and app registrations. Selected roles on the right panel include eop-sre and Paragon Testers.
  4. Verify the selected assignments.
    Figure 8: Verify users and groups Managing app interface for JRD Demo 2026. Users and groups section lists Paragon Testers and eop-sre assigned with Group object type. Success notification confirms application assignment.
  5. Save the configuration.
Note:

Users who are not assigned to the Enterprise Application cannot authenticate through the application.

Configure Attributes and Claims

Routing Director requires a NameID and additional user attributes to create user sessions and apply role mappings.

  1. Navigate to the created Enterprise Application, and click Single sign-on (see Figure 2). The Single sign-on page is displayed.

  2. Select SAML as the sign-on method on the Single Sign-on page.

    The SAML-based Sign-on page is displayed.

Confirm Default Claims

  1. Navigate to Attributes & Claims and click Edit. The Attributes & Claims page appears.
  2. Verify the existing claim configuration. Click the Unique User Identifier (Name ID).
    Figure 9: Configure Unique User Identifier (Name ID) Configuration screen for Attributes and Claims in SAML-based SSO, showing required claim Name ID with value user.userprincipalname and additional claims for email, given name, surname, and user principal name with options to add or adjust claims.
  3. Ensure that the Name identifier format is set to Email Address.
  4. Confirm that the Source attribute is user.userprincipalname.
    Figure 10: Configure Source and Source attribute Configuration screen for setting up a SAML claim with fields: Name as nameidentifier, Namespace as http://schemas.xmlsoap.org/ws/2005/05/identity/claims, Name Identifier Format as Email address, Source as Attribute, and Source Attribute as user.userprincipalname.
  5. Remove all additional prepopulated default claims. Click the trashcan icon next to a claim.
    Figure 11: Delete additional claims User interface of an identity system showing additional claims list with claim names, type as SAML, and user attribute values. Navigation menu includes options like App registrations and Conditional Access. A Delete option is visible.
  6. A deletion confirmation pop-up appears. Click OK to confirm the deletion of the additional claim. Repeat and delete all additional claims.
  7. Confirm that only the required claim Unique User Identifier (Name ID) is configured.

    Figure 12: Verify attributes and claims Configuration interface for managing Attributes and Claims in SAML-based SSO. Left sidebar lists navigation options. Main panel shows required claim details with claim name Unique User Identifier, type SAML, and value user.userprincipalname. Notification indicates SSO user claims successfully saved.

Configure FirstName and LastName Claims

Create the FirstName Claim
  1. Click Add new claim at the top of the Attributes & Claims page. The Manage claim page is displayed.
  2. Configure the following values:
    Table 1: Add FirstName Claim
    Field Value
    Name Enter FirstName.
    Source Select Attribute.
    Source Attribute Enter user.givenname.
    Figure 13: Add FirstName claim Azure AD portal Manage claim page showing fields to configure SAML claims, including Name set to FirstName, Source set to Attribute, and Source attribute set to user.givenname. Save and Discard buttons are at the top.
  3. Save the claim and confirm the configuration in the Additional claims list on the Attributes & Claims page.
Create the LastName Claim
  1. Click Add new claim at the top of the Attributes & Claims page. The Manage claim page is displayed.
  2. Configure the following values:
    Table 2: Add LastName claim
    Field Value
    Name Enter LastName
    Source Select Attribute.
    Source Attribute Enter user.surname.
  3. Save the claim and confirm the configuration in the Additional claims list on the Attributes & Claims page.

Configure the Role Claim

Use a Role claim to map Microsoft Entra ID groups to Routing Director roles.

  1. Click Add new claim at the top of the Attributes and Claims page. The Manage claim page is displayed.
  2. Configure the following values:
    Table 3: Configure the Role claim
    Field Value
    Name Enter Role
    Source Select Attribute.
    Expand Claim Conditions.
    User type Select Members from the drop-down list.
    Scoped Groups Click Select Groups and search for and select the previously added group member. Search interface showing "eop-sre" group with email domain juniper.net selected. Trash icon available to remove selection.
    Source Select Attribute.
    Value Enter the role name defined in Routing Director which corresponds to the role of the group you just selected. Select the role name within quotes to add the text. Configuration interface for claim conditions in an identity management system, showing settings for user type as Members, scoped groups with 1 group selected, source as Attribute, and editing SuperUser in a text input field. Advanced SAML claims options section is collapsed at the bottom.
    Repeat these steps for additional groups and role mappings. Add attribute values corresponding to those member groups.

    Ensure that the claim value exactly matches the Routing Director role name configured for SAML role mapping.

  3. Save and verify the configuration.

  4. Verify all the Attributes and Claims configuration.

    Figure 14: Verify all attributes and claims Configuration screen for Attributes and Claims in SAML-based SSO setup, showing required and additional claims mapping user attributes like userprincipalname, givenname, surname, and role.
  5. Click Close to exit out of the Attributes & Claims page.

Verify Enterprise Application Configuration

  1. Review the Attributes & Claims configuration.
  2. Review the Users and Groups assignments.
  3. Verify the NameID configuration.
  4. Confirm that FirstName, LastName, and Role claims are present.
  5. Note down the required URLs from the Set up Enterprise-application-name section:
    • Login URL
    • Microsoft Entra Identifier
    • (Optional) Logout URL

    This information is required when configuring Routing Director as a SAML Service Provider.

    Figure 15: Copy the required URLs Microsoft Entra ID interface showing single sign-on setup for JRD Demo 2026 with fields for Login URL, Microsoft Entra Identifier, Logout URL, and SSO testing options.

The Enterprise Application is now ready to be integrated with Routing Director.

Configure Routing Director SAML Identity Provider

  1. In Routing Director, navigate to Organization Settings > Identity Providers.
  2. Click Add New Identity Provider (IdP). The Create Identity Provider page is displayed.
  3. Configure the following required SAML settings using the values from the Configure SAML Single Sign-On and Configure Attributes and Claims configuration:
    Table 4: Fields on the Create Identity Provider page
    Field Value
    Name Enter a unique name for the Identity Provider.
    Type Select SAML.
    Issuer Enter the Microsoft Entra Identifier URL.
    Name ID Format Select the appropriate NameID format (email address is commonly used). Select E-mail.
    Signing Algorithm Select the signing algorithm that matches the Entra ID configuration.
    Certificate Copy and paste the content of the Base64-encoded signing certificate from Entra ID.
    SSO URL Enter the Entra Login URL.
    Custom Logout URL If your organization uses coordinated logout with Entra ID, enter the Entra Logout URL endpoint. Otherwise, leave this field blank.
  4. Save the configuration to create the new IdP.

What's Next

Launch Routing Director from the Entra My Apps portal. Log in using your SSO log in credentials.
Go to Troubleshoot and Validate Microsoft Entra ID Configuration for troubleshooting instructions.