Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Cisco Secure Firewall - Secur…
In brief
The article now uses a Cisco FQDN placeholder for the SAML metadata URL and emphasizes that Identifier and Reply URL examples must be verified against the intended Cisco endpoints and trusted domains.
What Entra admins need to know
Review these values in new and existing deployments, and do not use example or placeholder domains in production.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
On the Set up single sign-on with SAML page, enter the values for the following fields:
In the Identifier text box, type a URL using the following pattern:
https://<SUBDOMAINYOUR_CISCO_FQDN>.YourCiscoServer.com//saml/sp/metadata/<Tunnel_Group_Name>In the Reply URL text box, type a URL using the following pattern:
https://<YOUR_CISCO_ANYCONNECT_FQDN>/+CSCOE+/saml/sp/acs?tgname=<Tunnel_Group_Name>
@@ -4,7 +4,8 @@ description: Learn how to configure single sign-on between Microsoft Entra ID an ms.reviewer: celested ms.topic: how-to-ms.date: 05/20/2024+ms.date: 10/01/2026+ai-usage: ai-assisted # Customer intent: As an IT administrator, I want to learn how to configure single sign-on between Microsoft Entra ID and Cisco Secure Firewall - Secure Client so that I can control who has access to Cisco Secure Firewall - Secure Client, enable automatic sign-in with Microsoft Entra accounts, and manage my accounts in one central location. --- @@ -71,17 +72,23 @@ Follow these steps to enable Microsoft Entra SSO. 1. On the **Set up single sign-on with SAML** page, enter the values for the following fields: 1. In the **Identifier** text box, type a URL using the following pattern: - `https://<SUBDOMAIN>.YourCiscoServer.com/saml/sp/metadata/<Tunnel_Group_Name>`+ `https://<YOUR_CISCO_FQDN>/saml/sp/metadata/<Tunnel_Group_Name>` 1. In the **Reply URL** text box, type a URL using the following pattern: `https://<YOUR_CISCO_ANYCONNECT_FQDN>/+CSCOE+/saml/sp/acs?tgname=<Tunnel_Group_Name>` + > [!IMPORTANT]+ > The **Identifier** and **Reply URL** values shown in this article are examples only. Before you configure SSO, verify that these values reference the correct endpoints for your Cisco Secure Firewall environment. Don't use example or placeholder domains in production. Contact Cisco TAC or the [Cisco Secure Firewall - Secure Client support team](https://www.cisco.com/c/en/us/support/index.html) for the appropriate values.+ > [!NOTE] > `<Tunnel_Group_Name>` is a case-sensitive and the value must not contain dots "." and slashes "/". > [!NOTE] > For clarification about these values, contact Cisco TAC support. Update these values with the actual Identifier and Reply URL provided by Cisco TAC. Contact the [Cisco Secure Firewall - Secure Client support team](https://www.cisco.com/c/en/us/support/index.html) to get these values. You can also refer to the patterns shown in the **Basic SAML Configuration** section. + > [!IMPORTANT]+ > **Security best practice:** For new and existing deployments, verify that all configured **Identifier** and **Reply URL** values reference the intended endpoints and trusted domains before you enable SAML SSO. Example or placeholder domains are for documentation purposes only and must not be used in production.+ 1. On the **Set up single sign-on with SAML** page, in the **SAML Signing Certificate** section, find **Certificate (Base64)** and select **Download** to download the certificate file and save it on your computer.  