Microsoft Entra External ID
Standards

Saml Ws Federation Self Service Sign Up

In brief

The standalone article covering prerequisites and steps for adding a SAML or WS-Fed identity provider to a user flow was removed and consolidated into a single article referenced by the federation documentation.

What Entra admins need to know

No administrator action is stated; use the consolidated article for these instructions.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

deleted file mode 100644

title: SAML/WS-Fed federation for self-service sign-up description: Set up direct federation with SAML 2.0 or WS-Fed identity providers (IdP) and enable self-service sign-up for external users, who can sign in with their own work accounts. ms.topic: how-to ms.date: 05/07/2025 ms.custom: it-pro, ms.collection: M365-identity-device-management #customer intent: As an IT admin setting up federation with an external organization's SAML/WS-Fed identity provider, I want to invite users from that organization to sign in to my Microsoft Entra tenant with their work account.

Add the SAML/WS-Fed identity provider to a user flow

[!INCLUDE applies-to-external-only]

Once you've configured federation with a SAML or WS-Fed identity provider by following the steps in Add federation with SAML/WS-Fed identity providers, the identity provider is set up in your external tenant, but it's not yet available in any of the sign-in pages.

Prerequisites

Add the identity provider to a user flow

  1. Sign in to the Microsoft Entra admin center as at least an External ID User Flow Administrator.

  2. Switch to your external tenant: Select the Settings icon in the top menu, and then switch to your external tenant.

  3. Browse to Entra ID > External Identities > User flows.

  4. Select the user flow where you want to add the identity provider.

    :::image type="content" source="media/saml-ws-federation-self-service-sign-up/select-user-flow.png" alt-text="Screenshot showing where to select the user flow.":::

  5. Under Settings, select Identity providers.

  6. Under Other Identity Providers, select the identity provider.

    :::image type="content" source="media/saml-ws-federation-self-service-sign-up/select-identity-provider.png" alt-text="Screenshot showing how to select the identity provider on the SAML WS-Fed page.":::

  7. Select Save.

Next steps

Follow the steps in Test your sign-up and sign-in user flow to simulate a user’s sign-up or sign-in experience with your app.

Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…