Using Microsoft Entra ID (Azure AD) SSO to Log in to Bob! Desk (SAML 2.0)
This guide describes how to connect your Microsoft Entra ID environment (formerly Azure Active Directory) to Bob! Desk via SAML 2.0. The goal is to let your users log in to the platform with their corporate Microsoft credentials.
Environments: production and test (staging)
Bob! Desk has a test environment (staging) separate from production. To validate the SSO connection before enabling it for your users, create a SAML application in Entra ID with the values from the "Staging" column, then a second application with the "Production" values when you are ready.
| Item | Production | Staging (test) |
|---|---|---|
| Entity ID (Service Provider identifier) | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata |
| Reply URL (ACS URL) | https://general-api.bob-desk.com/auth/v1/sso/saml/acs | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/acs |
| Sign-on URL (optional) | https://app.bob-desk.com | https://staging.bob-desk.com |
| Metadata URL (optional) | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata |
| Metadata URL, download (optional) | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true | https://staging-general-api.bob-desk.com/auth/v1/sso/saml/metadata?download=true |
The steps below use the production values.
Steps to perform in Entra ID (Azure AD)
Step 1 — Open the application management
- Log in to the Azure portal with an administrator account.
- Go to Azure Active Directory → Enterprise applications.
- Click "+ New application".
Step 2 — Create a custom SAML application
- Choose "Create your own application".
- Give it a clear name, for example:
SSO - [Your company name] to Bob! Desk. - Select "Integrate any other application you don't find in the gallery (Non-gallery application)".
- Click Create.
Step 3 — Configure SAML authentication
Once the application is created:
- In the "Single sign-on" section, select SAML as the method.
- Fill in the following fields:
| Field in Azure | Value to enter |
|---|---|
| Identifier (Entity ID) | https://general-api.bob-desk.com/auth/v1/sso/saml/metadata |
| Reply URL (Assertion Consumer Service URL) | https://general-api.bob-desk.com/auth/v1/sso/saml/acs |
| Sign-on URL (optional) | https://app.bob-desk.com |
The ACS URL and the Entity ID must match the values above exactly. Any extra space or wrong character will prevent SSO from working.
Step 4 — Configure user attributes (claims)
In the "User Attributes & Claims" section, check that the following claims are configured:
| Claim name | Attribute source |
|---|---|
email | user.mail |
given_name | user.givenname |
family_name | user.surname |
name | user.userprincipalname |
The email claim must be present and match the user's primary address: it is the unique identifier used by Bob! Desk.
Step 5 — Download the IdP metadata
On the same page, under the "SAML Signing Certificate" section:
- Click Download Metadata XML. The downloaded file contains the IdP Entity ID, the SSO URL and the public X.509 certificate.
- Keep this file, you will need to send it to us.
Step 6 — Assign the authorized users or groups
- In the side menu, open "Users and groups".
- Click Add user/group.
- Select the users or groups that will have access to Bob! Desk.
- Click Assign.
Information to send us
Once the configuration is complete, send an email to tech@bob-desk.fr (click for a pre-filled email) containing:
- The metadata XML file downloaded in step 5 (or, failing that, the following values extracted from it):
- IdP Entity ID: e.g.
https://sts.windows.net/{tenant-id}/ - SSO URL (Login URL): e.g.
https://login.microsoftonline.com/{tenant-id}/saml2 - X.509 certificate (contained in the XML)
- IdP Entity ID: e.g.
- The email domain(s) of the users who will log in via SSO (e.g.
company.com). The domain is the part of the email address after the "@"; if there are several, please list them all. - The environment concerned: production or staging.
We will use this data to enable the SSO connection on the Bob! Desk side and validate the integration.
Verifying the SSO
Once our team has completed the integration:
- Go to the Bob! Desk SSO login page: https://app.bob-desk.com/sso-login (or https://staging.bob-desk.com/sso-login for the test environment).
- Enter your corporate email address.
- You will be redirected to your organization's Microsoft login page.
- After authentication, you are automatically redirected to Bob! Desk and logged in.
For more information, or to go further with the SAML 2.0 SSO configuration on Supabase, which Bob! Desk authentication relies on, you can also refer to the official Supabase documentation: https://supabase.com/docs/guides/auth/enterprise-sso/auth-sso-saml
