SSO Integration Between Routing Director and Microsoft Entra ID Overview

This topic provides an overview of IdP-initiated SAML 2.0 SSO between Juniper Routing Director and Microsoft Entra ID.

Juniper Routing Director supports centralized authentication through external identity providers. Microsoft Entra ID provides cloud-based identity and access management capabilities that can be used to authenticate Routing Director users through SAML 2.0. You can set up IdP-initiated SAML 2.0 SSO between Juniper Routing Director (as the SP) and Microsoft Entra ID (as the IdP).

In this integration:

  • Routing Director acts as the Service Provider (SP).
  • Microsoft Entra ID acts as the Identity Provider (IdP).
  • Entra ID authenticates users and sends signed SAML assertions to Routing Director.
  • Routing Director uses SAML claims and group information to determine user roles and permissions.

SSO Authentication Flow

The authentication process follows an IdP-initiated workflow:

  1. User launches Routing Director from the Entra ID My Apps portal.
  2. Entra ID authenticates the user.
  3. Entra ID generates and signs a SAML assertion.
  4. Routing Director validates the assertion.
  5. Routing Director maps user attributes and groups to internal roles.
  6. User gains access based on assigned permissions.
Note:

Routing Director currently supports IdP-initiated SSO only. You cannot initiate login directly from the Routing Director login page. You must launch from the Entra ID My Apps portal.

Prerequisites

Before you configure Single Sign-On (SSO) between Routing Director and Microsoft Entra ID, ensure that both environments are prepared and that the required SAML configuration information is available.

Routing Director Requirements

Verify that the following prerequisites are met in Routing Director:

  • Routing Director is deployed and accessible.
  • You have superuser privileges to access the Organization Settings page.
  • Network Time Protocol (NTP) synchronization is functioning correctly on all Routing Director cluster nodes. Time differences between the Identity Provider (IdP) and Service Provider (SP) can cause SAML assertion validation failures.
  • At least one local superuser account is available as a break-glass account during deployment and testing.
  • Local user IDs do not conflict with user IDs that will authenticate through SSO.

Microsoft Entra ID Requirements

Verify that the Microsoft Entra ID tenant meets the following requirements:

  • You have one of the following administrative roles:
    • Global Administrator
    • Cloud Application Administrator
    • Application Administrator
  • You can create and manage Enterprise Applications.
  • You can configure SAML-based Single Sign-On.
  • You can modify application claims and attributes.
  • You can assign users and groups to the Enterprise Application.

For information about onboarding non-gallery applications and managing SAML-based SSO in Microsoft Entra ID, refer to the Microsoft Entra ID documentation.

SAML Trust Parameters

Routing Director and Microsoft Entra ID exchange a set of trust parameters to establish the SAML relationship. Table 1 identifies the values used during configuration.

Table 1: SAML Trust Parameters
Parameter Microsoft Entra ID Value Routing Director Field
IdP Entity ID Microsoft Entra Identifier Issuer
IdP SSO URL Login URL SSO URL
IdP Signing Certificate Certificate (Base64) Certificate
SP Entity ID Identifier (Entity ID) Assertion Consumer Service (ACS) URL
SP ACS URL Reply URL Assertion Consumer Service (ACS) URL

SAML Claims and Role Mapping

Routing Director controls user access through predefined internal roles. To support role-based access control (RBAC), user attributes or group membership information must be included in the SAML assertion generated by Microsoft Entra ID.

Routing Director supports mapping IdP groups to Routing Director roles from the Organization Settings page. Plan your authorization model before deployment and determine whether group membership or application roles will be used for role assignment.

In Microsoft Entra ID, configure these mappings from the Attributes & Claims section of the Enterprise Application.

NameID Configuration

The NameID attribute uniquely identifies the authenticated user.

By default, Microsoft Entra ID uses user.userprincipalname (UPN) as the NameID value. Because many SAML service providers expect an email-format identifier, this default setting is appropriate for Routing Director users who are always identified by their email addresses.

Group and Role Claims

To enable RBAC in Routing Director:

  • Configure Microsoft Entra ID to include group membership or application role claims in the SAML assertion.
  • Create corresponding role mappings in Routing Director.
  • Verify that claim values match the Routing Director role mappings.

This approach enables Microsoft Entra ID to act as the authoritative source for user authorization while Routing Director enforces access based on its configured roles.

What's Next?

Configure the Microsoft Entra ID Enterprise Application for Juniper Routing Director SAML authentication.

Go to Configure SSO Between Routing Director and Microsoft Entra ID.