You’ll need to configure settings in Microsoft Entra ID (formerly Azure AD) to finalize the setup for Identity Federation.
- Open Microsoft Entra ID.
- Navigate to Enterprise applications - All Applications.
- Select New application.

- Select Add from the gallery> Microsoft Entra ID SAML Toolkit.

- Type the name you want for the application.

- Navigate to Visit Enterprise Applications.
- Select
<your_app>.

- Select Manage > Single sign-on.
- Select SAML.
- On theSet up single sign-on with SAML page, edit the Basic SAML Configuration.

- Change the following fields in the Basic SAML Configuration.
Identifier (Entity ID): Examples:
urn:treasuredata:sso:aws:<your_account_name>urn:treasuredata:sso:aws-tokyo:<your_account_name>urn:treasuredata:sso:eu01:<your_account_name>
Reply URL: https://sso.treasuredata.com/login/callback
Sign-on URL:
- US:
https://console.us01.treasuredata.com/users/initiate_sso?account_name=<your_account_name> - JP:
https://console.treasuredata.co.jp/users/initiate_sso?account_name=<account_name> - Europe:
https://console.eu01.treasuredata.com/users/initiate_sso?account_name=<account_name>
Locate the Entity ID in the TD Console under**Administration > Sign In Settings > Identity Federation.
Go back to the Azure console. Go to Attributes & Claims** section. Choose the value you want to use for the Unique User Identifier. If
user.mailis indicated, you can set up the TD user with their email. If the value is[user.name](<http://user.name>), set the field with the user name.Select Save.
Navigate to Enterprise applications - All Applications.
Select the desired application.
SelectUsers and groups > Add user.

Add users and assign roles.
After users are assigned, navigate to Single sign-on.

Gather the following items from the Single sign-on page to complete your configuration from within the TD Console. Ensure you are checking the configuration for the correct Entity ID.
- US:

If you receive the following error, "Could not authenticate you from Auth0 because "Recipient is invalid. configured: https://sso.treasuredata.com/login/callback".
Review the URL of your identity server. It is possible that it is set to the incorrect URL.