> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md).

# Microsoft Azure：SAML/Entra IDでログイン

{% hint style="info" %}
この機能は、 **有料** プランでのみ利用可能で、デフォルトでは有効になっていません。この機能を有効にしたい場合は、Aikido内の右下にあるチャットからご連絡ください。
{% endhint %}

> Gitプロバイダー経由の自動オンボーディングの代わりにSAMLログインに切り替えると、GitHub、Bitbucket、またはAzure DevOpsからのチームのインポートは今後動作しなくなります。今後は、AikidoのUIまたは [アクセスプロファイルを通じて、チームを手動で管理する必要があります。](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended.md)

## アカウントでのSAML設定 <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**手順 1。** 移動先 [**一般設定**](https://app.aikido.dev/settings/account) をクリックし、**「SAML認証を有効にする」**

![GitHubアカウントのSAML認証を有効にするオプションがあるワークスペース情報画面。](/files/ad278b37943846d49d04ea8cb2e5fa6fec2a42c7)

**手順 2。** コピー **すべての詳細** をIDプロバイダーにコピーします。以下の手順を参照してください。

![設定に必要なURLとName ID形式を表示するSAML認証セットアップ画面。](/files/8ead9fa04fd75445d0fdeb92ad6f5dc363e7059b)

### Azureで続行 <a href="#continue-in-azure" id="continue-in-azure"></a>

**手順 1。** 移動先 **Microsoft Entra ID**.

**手順 2。** 次をクリックします： **追加** ドロップダウンを開いて選択 **エンタープライズ アプリケーション**.

![Microsoft Azure Active Directory に新しいエンタープライズ アプリケーションを追加しています。](/files/81f524b95f253952b5de3c7f8aa58adf3b21ecb6)

**手順 3。** クリック **独自のアプリケーションを作成**、アプリの名前を選び、「非ギャラリー」を選択します。

![統合用に「Aikido-SSO」という名前のカスタム非ギャラリー アプリケーションを作成しています。](/files/8c111448f0aa64ad0922f029a8eab4e8e1cb99a3)

**手順 4。** 次を選択します **シングルサインオンを設定**.

![Aikido-SSO アプリのセットアップ: ユーザーを割り当て、Microsoft Entra でシングルサインオンを構成します。](/files/286ab433ffef067904462198428a1fb020391219)

**ステップ 5。** 次をクリックします： **SAML** オプションを選択してください。

![Aikido-SSO で安全なアプリ認証のために SAML シングルサインオンを有効にします。](/files/d18e4a65845f45ef6c2848bd42e2cc304546159e)

**ステップ 6。** オン **手順 1**、次をクリックします: **編集。**

![基本 SAML 構成: 必要な識別子と返信 URL のフィールドを編集します。](/files/7af14e4e2303089198f7696c507af5f38e24b662)

**ステップ 7。** 次を入力してください **エンティティ ID** および **ACS URL** Aikido に表示されているとおり。

![エンティティ ID と返信 URL フィールドを指定した SAML SSO の構成画面。](/files/fd8c3f2a74c765dd0f588ce799366cbfd7aa1442)

**手順 8。** で **手順 2**、次をクリックします: **編集。**

![編集可能なオプションが強調表示された、ユーザー属性とクレームのマッピング。](/files/c7f20337dd5ecdfd3b2414a95cf2a4592577ac7b)

**手順 9。** 次をクリックします： **一意のユーザー識別子（Name ID）**。\
オプション: このページ上部の「新しいクレームを追加」をクリックすると、追加できます [カスタム属性](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced.md) を SAML に。詳細情報 [こちら](https://help.aikido.dev/doc/microsoft-azure-custom-attributes-with-saml--entra-id/docFaysVwVZy).

![強調表示された SAML クレーム: ユーザー識別用の一意のユーザー識別子（Name ID）。](/files/376c4e1ac5321189100771081ba1c402ff1d4544)

**手順 10。** 必ず設定してください **ソース属性** を次に設定します: `user.mail` こちらで確認できます。

![Azure AD でユーザーのメールアドレスを名前識別子として使用する SAML クレームを構成しています。](/files/ad21adbd9972699e63a33a9a1bc47fe3880b261f)

**手順 11。** 手順 3 で **証明書（Base64）** と手順 4 では **ログイン URL** および **Mircosoft Entra 識別子**。これらを Aikido にコピーして貼り付けてください。

### Aikidoに戻る <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* 次を入力してください **Entity ID / Issuer**, **シングルサインオン URL** および **X.509証明書** Azure に表示されているとおり。
* また、 **会社ドメイン** も入力して、シングルサインオンURLなしで人がログインできるようにしてください。

![シングルサインオン（SSO）資格情報を構成するための SAML 認証セットアップフォーム。](/files/0e38fd9a1ccaf3b189cbf5646e798a8cf4ff39cf)

> 成功です！Azure の SAML アプリにアクセスできる人は、Aikido ワークスペースに自動参加できるようになりました。

### SAMLクライアントを使用してユーザーがログインするための2つのオプション <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**オプション1. SSOリンクを直接使用**

ログインリンクをコピーして、他のユーザーと社内で共有してください。

![ログインリンクを管理またはコピーするオプションを備えたSAML認証設定。](/files/3be45d87e9f29d5fe9157d43ff6f90932df80083)

**オプション2。** Aikidoのログイン画面に移動し、 **SSO経由でログイン** を選択して、メールアドレスを入力する **重要**：メールアドレスには、設定済みの会社ドメインが含まれている必要があります。

![Google、Microsoft、または SSO でワンクリックのログインとサインアップ。クレジットカードは不要です。](/files/5328eb6fc4a384e91130e9aa62cb5da8ef879f15)

![Google、Microsoft、またはメールでのサインイン オプションを提供するログイン画面。](/files/1769900b4df8ab61a95e97537eac3ce47254adfb)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
