Using Microsoft Entra ID (Azure AD) SSO to Log in to Bob! Desk (SAML 2.0)

This guide describes how to connect your Microsoft Entra ID environment (formerly Azure Active Directory) to Bob! Desk via SAML 2.0. The goal is to let your users log in to the platform with their corporate Microsoft credentials.

Environments: production and test (staging)

Bob! Desk has a test environment (staging) separate from production. To validate the SSO connection before enabling it for your users, create a SAML application in Entra ID with the values from the "Staging" column, then a second application with the "Production" values when you are ready.

ItemProductionStaging (test)
Entity ID (Service Provider identifier)https://general-api.bob-desk.com/auth/v1/sso/saml/metadatahttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata
Reply URL (ACS URL)https://general-api.bob-desk.com/auth/v1/sso/saml/acshttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/acs
Sign-on URL (optional)https://app.bob-desk.comhttps://staging.bob-desk.com
Metadata URL (optional)https://general-api.bob-desk.com/auth/v1/sso/saml/metadatahttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata
Metadata URL, download (optional)https://general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=truehttps://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true

The steps below use the production values.

Steps to perform in Entra ID (Azure AD)

Step 1 — Open the application management

  1. Log in to the Azure portal with an administrator account.
  2. Go to Azure Active Directory → Enterprise applications.
  3. Click "+ New application".

Step 2 — Create a custom SAML application

  1. Choose "Create your own application".
  2. Give it a clear name, for example: SSO - [Your company name] to Bob! Desk.
  3. Select "Integrate any other application you don't find in the gallery (Non-gallery application)".
  4. Click Create.

Step 3 — Configure SAML authentication

Once the application is created:

  1. In the "Single sign-on" section, select SAML as the method.
  2. Fill in the following fields:
Field in AzureValue to enter
Identifier (Entity ID)https://general-api.bob-desk.com/auth/v1/sso/saml/metadata
Reply URL (Assertion Consumer Service URL)https://general-api.bob-desk.com/auth/v1/sso/saml/acs
Sign-on URL (optional)https://app.bob-desk.com

Step 4 — Configure user attributes (claims)

In the "User Attributes & Claims" section, check that the following claims are configured:

Claim nameAttribute source
emailuser.mail
given_nameuser.givenname
family_nameuser.surname
nameuser.userprincipalname

Step 5 — Download the IdP metadata

On the same page, under the "SAML Signing Certificate" section:

  1. Click Download Metadata XML. The downloaded file contains the IdP Entity ID, the SSO URL and the public X.509 certificate.
  2. Keep this file, you will need to send it to us.

Step 6 — Assign the authorized users or groups

  1. In the side menu, open "Users and groups".
  2. Click Add user/group.
  3. Select the users or groups that will have access to Bob! Desk.
  4. Click Assign.

Information to send us

Once the configuration is complete, send an email to tech@bob-desk.fr (click for a pre-filled email) containing:

  1. The metadata XML file downloaded in step 5 (or, failing that, the following values extracted from it):
    • IdP Entity ID: e.g. https://sts.windows.net/{tenant-id}/
    • SSO URL (Login URL): e.g. https://login.microsoftonline.com/{tenant-id}/saml2
    • X.509 certificate (contained in the XML)
  2. The email domain(s) of the users who will log in via SSO (e.g. company.com). The domain is the part of the email address after the "@"; if there are several, please list them all.
  3. The environment concerned: production or staging.

We will use this data to enable the SSO connection on the Bob! Desk side and validate the integration.

Verifying the SSO

Once our team has completed the integration:

  1. Go to the Bob! Desk SSO login page: https://app.bob-desk.com/sso-login (or https://staging.bob-desk.com/sso-login for the test environment).
  2. Enter your corporate email address.
  3. You will be redirected to your organization's Microsoft login page.
  4. After authentication, you are automatically redirected to Bob! Desk and logged in.

For more information, or to go further with the SAML 2.0 SSO configuration on Supabase, which Bob! Desk authentication relies on, you can also refer to the official Supabase documentation: https://supabase.com/docs/guides/auth/enterprise-sso/auth-sso-saml