> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md).

# Microsoft Azure: SAML/Entra IDでログイン

{% hint style="info" %}
この機能は、 **有料** プランでのみ利用可能で、デフォルトでは有効になっていません。この機能を有効にしたい場合は、Aikido内の右下隅にあるチャットからご連絡ください。
{% endhint %}

> Gitプロバイダー経由の自動オンボーディングではなくSAMLログインに切り替えると、GitHub、Bitbucket、またはAzure DevOpsからのチームのインポートは使えなくなります。今後は、AikidoのUIまたは [アクセスプロファイル](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended.md)

## アカウントでのSAML設定 <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**ステップ 1.** 移動して [**一般設定**](https://app.aikido.dev/settings/account) をクリックし、'**SAML認証を有効にする'**

![GitHubアカウントのSAML認証を有効にするオプションがあるワークスペース情報画面。](/files/ad278b37943846d49d04ea8cb2e5fa6fec2a42c7)

**ステップ 2.** コピー **すべての詳細** をIDプロバイダーにコピーしてください。以下の手順を参照してください。

![設定に必要なURLとName ID形式を示すSAML認証設定画面。](/files/8ead9fa04fd75445d0fdeb92ad6f5dc363e7059b)

### Azureで続行 <a href="#continue-in-azure" id="continue-in-azure"></a>

**ステップ 1.** 移動して **Microsoft Entra ID**.

**ステップ 2.** 次にある **追加** ドロップダウンを開いて選択 **エンタープライズ アプリケーション**.

![Microsoft Azure Active Directory に新しいエンタープライズ アプリケーションを追加しています。](/files/81f524b95f253952b5de3c7f8aa58adf3b21ecb6)

**ステップ 3.** をクリックし、 **独自のアプリケーションを作成**、アプリの名前を選択し、'Non-gallery' を選択します。

![統合作業用に、"Aikido-SSO" というカスタムの non-gallery アプリケーションを作成しています。](/files/8c111448f0aa64ad0922f029a8eab4e8e1cb99a3)

**ステップ 4.** 選択します **シングルサインオンを設定**.

![Aikido-SSO アプリの設定: ユーザーを割り当て、Microsoft Entra でシングルサインオンを構成します。](/files/286ab433ffef067904462198428a1fb020391219)

**ステップ 5.** 次にある **SAML** オプションを選択してください。

![Aikido-SSO でアプリケーションを安全に認証するために SAML シングルサインオンを有効にします。](/files/d18e4a65845f45ef6c2848bd42e2cc304546159e)

**ステップ 6.** オン **手順 1**に戻って、 **編集。**

![基本 SAML 構成: 必要な識別子と返信 URL のフィールドを編集します。](/files/7af14e4e2303089198f7696c507af5f38e24b662)

**ステップ 7.** 次を入力してください **エンティティ ID** に、 **ACS URL** Aikido に表示されているとおり。

![エンティティ ID と返信 URL の項目を指定した SAML SSO の設定画面。](/files/fd8c3f2a74c765dd0f588ce799366cbfd7aa1442)

**手順 8。** で **手順 2**に戻って、 **編集。**

![編集可能なオプションが強調表示されたユーザー属性とクレームのマッピング。](/files/c7f20337dd5ecdfd3b2414a95cf2a4592577ac7b)

**手順 9。** 次にある **一意のユーザー識別子（Name ID）**。\
オプション: このページ上部の 'Add new claim' をクリックすると、追加できます [カスタム属性](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced.md) を SAML に。詳細 [こちら](https://help.aikido.dev/doc/microsoft-azure-custom-attributes-with-saml--entra-id/docFaysVwVZy).

![強調表示された SAML クレーム: ユーザー識別用の一意のユーザー識別子（Name ID）。](/files/376c4e1ac5321189100771081ba1c402ff1d4544)

**手順 10。** 設定するようにしてください **ソース属性** を `user.mail` こちらで確認できます。

![Azure AD でユーザーのメールアドレスを名前識別子として使用する SAML クレームを構成しています。](/files/ad21adbd9972699e63a33a9a1bc47fe3880b261f)

**手順 11。** 手順 3 で **証明書（Base64）** をダウンロードでき、手順 4 では **ログイン URL** に、 **Mircosoft Entra 識別子**。これらは Aikido にコピーして貼り付けてください。

### Aikidoに戻る <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* 次を入力してください **Entity ID / Issuer** Azure の **Microsoft Entra 識別子**、および **シングルサインオン URL** Azure の **ログイン URL** （どちらも手順 11 から）、さらに **X.509証明書** Azure に表示されているとおり。
* また、 **会社のドメイン** も入力して、シングルサインオンURLなしで人々がログインできるようにしてください。

![シングルサインオン（SSO）認証情報を構成するための SAML 認証設定フォーム。](/files/0e38fd9a1ccaf3b189cbf5646e798a8cf4ff39cf)

> 成功！Azure の SAML アプリにアクセスできる人は、これから Aikido ワークスペースに自動登録できるようになります。

### SAMLクライアントを使ってユーザーがログインするための2つの方法 <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**オプション1. SSOリンクを直接使用**

ログインリンクをコピーし、他のユーザーに社内で共有してください。

![ログインリンクを管理またはコピーするオプションがあるSAML認証設定。](/files/3be45d87e9f29d5fe9157d43ff6f90932df80083)

**オプション2。** Aikidoのログイン画面に移動し、 **SSOでログイン** を選択して、メールアドレスを入力する **重要**：メールアドレスには、設定済みの会社ドメインが含まれている必要があります。

![Google、Microsoft、または SSO でワンクリックのログインとサインアップ。クレジットカードは不要です。](/files/5328eb6fc4a384e91130e9aa62cb5da8ef879f15)

![Google、Microsoft、またはメールでのサインイン オプションを提供するログイン画面。](/files/1769900b4df8ab61a95e97537eac3ce47254adfb)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
