unable to set up SAML SSO with Entra ID
- Dominant language
- Python
- Stars
- 44.8k
- Forks
- 4.9k
- Avg merge
- 21h 10m
- Merged PRs (30d)
- 635
Description
### Environment
SaaS (https://sentry.io/)
### Steps to Reproduce
1. Create an MS Entra ID (former Azure) organisation
2. Add Entra ID user to a secure group
4. Try to configure SSO following the steps on this page https://docs.sentry.io/organization/authentication/sso/azure-sso/
### Expected Result
SSO is configured.
### Actual Result
SSO is not configured and no error is shown.
The no error showing in the [UI is a result of this known issue](https://github.com/getsentry/sentry/issues/96631), which is blocking the troubleshooting of the affected user.
What have been done so far:
- Confirmed all attributes set in Sentry are sent in the SAMLResponse
- The attributes are valid and match an existing user in Sentry. The email address has dots and capitals, when reproducing the same email it worked on a test organisation.
- Confirmed additional claims do not affect result.
Full information is available in the internal Linear ticket.
### Product Area
Settings - Auth
### Link
_No response_
### DSN
_No response_
### Version
_No response_
Contributor guide
Research direction
Start with the SSO setup instructions at docs.sentry.io/organization/authentication/sso/azure-sso/ and review the linked issue #96631 about missing UI errors. Compare the reported Entra ID SAML configuration and claims with the working test organisation; done means identifying why setup fails and providing a visible, actionable error or a confirmed configuration fix.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- authentication, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 32/100