Add Microsoft Entra ID as a single sign-on provider
Add Genesys Cloud as an application that organization members can access with the credentials to their Microsoft Entra ID Premium or Free Microsoft Entra ID account.
- Genesys Cloud does not support assertion encryption for single sign-on third-party identity providers. The Genesys Cloud log in service requires Transport Layer Security (TLS). Since the channel is encrypted, there is no need to encrypt parts of the message.
- Administrators can optionally disable the default Genesys Cloud login and enforce authentication using an SSO provider only. For more information, see Configure Genesys Cloud to authenticate with SSO only.
- Administrators can choose to store four additional certificates to ensure business continuity. If one certificate becomes invalid or expires, the integration is preserved if one of the additional certificates is valid.
There is a general problem when a Service Provider (SP) receives a SAML response from an Identity Provider (IdP) and their system clocks are not in sync. This problem can result in users getting locked out of their single sign-on when logging in. The problem might be caused by the length of the clock skew between the SP and the IdP. Clock skews between Genesys Cloud and your identity provider cannot be greater than 10 seconds.
- The Genesys Cloud desktop app does not support the installation of browser extensions. If you have configured an Azure Conditional Access policy that requires a browser extension, you will need to use a Genesys Cloud supported browser that has the Microsoft Entra ID extension installed. Single sign-on will not work using the desktop app in this configuration.
Configure Microsoft Entra ID
You can either configure the Genesys Cloud gallery application (preferred method) or create a custom Genesys Cloud application.
Assign users and groups to the Genesys Cloud application
After configuring either the Genesys Cloud gallery or a custom Genesys Cloud application, assign the users and groups to log in to Genesys Cloud using Microsoft Entra ID as the identity provider.
- In the Genesys Cloud custom application, click Users and groups.
- Click Add user.
- Click the appropriate users and groups.
- Click Assign.
Configure Genesys Cloud
Genesys Cloud configuration applies to both the Genesys Cloud gallery application and a custom Genesys Cloud application.
- In Genesys Cloud, click Admin.
- Under Integrations, click Single Sign-on.
- Click the ADFS/Microsoft Entra ID (Premium) tab.
Type the identity provider metadata gathered from Microsoft Entra ID.
Field Description Certificate To upload X.509 certificates for SAML signature validation, do one of the following.
- To upload a certificate, click Select Certificates to upload.
- Select the X.509 certificate.
- Click Open.
- Optionally, to load a backup certificate, repeat steps 1–3.
Or you can:
- Drag and drop your certificate file.
- Optionally, to load a backup certificate, repeat the first step.
Uploaded certificates appear with their expiration date. To remove a certificate, click X.
Note: To renew or update an expiring certificate, follow these instructions to upload X.509 certificates, repeating steps 1--3. You can upload up to five certificates to Genesys Cloud per SSO configuration, and Genesys Cloud chooses the correct certificate during single sign-on and logout.Issuer URI Type the Azure AD Identifier from the Microsoft Entra ID Genesys Cloud custom application.
Note: The issuer URI is a URL, not just the ID. Make sure that the URL is in the format “https://sts.windows.net/1234abcd5678efgh,” where the GUID is the Entity ID from Azure.Target URI Type the Login URLfrom the Microsoft Entra ID Genesys Cloud custom application. Single Logout URI Type the Logout URL from the Microsoft Entra ID Genesys Cloud custom application. Single Logout Binding Choose HTTP Redirect. Relying Party Identifier Type the Identifier (Entity ID) from the Microsoft Entra ID Genesys Cloud custom application.
Note: The SAML resource is the default for the app within Microsoft Entra ID. We recommend using the SAML resource as an Entity ID, as it is unique and readily available. If you are running multiple instances of the SSO integration on your Microsoft Entra ID instance, you can use a unique identifier as long as the IDP configuration in Genesys Cloud has the same identifier in the Relying Party Identifier field. Genesys Cloud uses this value to identify itself to the IDP. The Relying Party Identifier can be any value as long as it can uniquely identify Genesys Cloud to the identity provider.- Click Save.
Test the Microsoft Entra ID Genesys Cloud application
The Microsoft Entra ID Genesys cloud application testing applies to both the Genesys Cloud gallery application and the custom Genesys Cloud application.
- In the Single sign-on detail view in Microsoft Entra ID, click Test this application.
[NEXT] Was this article helpful?
Get user feedback about articles.