> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md).

# Microsoft Azure: SAML / Entra IDでログイン

{% hint style="info" %}
この機能は、 **有料** プランでのみ利用可能で、デフォルトでは有効になっていません。この機能を有効にしたい場合は、Aikido内の右下隅にあるチャットからご連絡ください。
{% endhint %}

> Gitプロバイダー経由の自動オンボーディングではなくSAMLログインに切り替えると、GitHub、Bitbucket、またはAzure DevOpsからのチームのインポートは今後機能しなくなります。今後は、AikidoのUIまたは [アクセスプロフィール](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-access-profiles-recommended.md)

## アカウントでのSAML設定 <a href="#setting-up-saml-in-your-account" id="setting-up-saml-in-your-account"></a>

**手順1。** 移動する [**一般設定**](https://app.aikido.dev/settings/account) をクリックし、'**SAML認証を有効化'**

![GitHub アカウントの SAML 認証を有効にするオプションがあるワークスペース情報画面。](/files/ad278b37943846d49d04ea8cb2e5fa6fec2a42c7)

**手順2。** コピー **すべての詳細を** をアイデンティティプロバイダーに設定してください。以下の手順をご覧ください。

![設定に必要な URL と Name ID 形式を示す SAML 認証のセットアップ画面。](/files/8ead9fa04fd75445d0fdeb92ad6f5dc363e7059b)

### Azure で続行 <a href="#continue-in-azure" id="continue-in-azure"></a>

**手順1。** 移動する **Microsoft Entra ID**.

**手順2。** をクリックします **追加** ドロップダウンを開いて選択 **エンタープライズ アプリケーション**.

![Microsoft Azure Active Directory に新しいエンタープライズ アプリケーションを追加しています。](/files/81f524b95f253952b5de3c7f8aa58adf3b21ecb6)

**手順3。** クリック **独自のアプリケーションを作成**、アプリの名前を選択して「Non-gallery」を選びます。

![連携のために「Aikido-SSO」という名前のカスタムな非ギャラリー アプリケーションを作成しています。](/files/8c111448f0aa64ad0922f029a8eab4e8e1cb99a3)

**手順4。** 選択してください **シングル サインオンを設定**.

![Aikido-SSO アプリケーションのセットアップ: ユーザーを割り当て、Microsoft Entra でシングル サインオンを構成します。](/files/286ab433ffef067904462198428a1fb020391219)

**ステップ 5。** をクリックします **SAML** オプションを選択してください。

![Aikido-SSO で安全なアプリケーション認証のために SAML シングル サインオンを有効にします。](/files/d18e4a65845f45ef6c2848bd42e2cc304546159e)

**ステップ 6。** オン **ステップ 1**に戻り、 **編集。**

![基本 SAML 構成: 必要な識別子と返信 URL のフィールドを編集します。](/files/7af14e4e2303089198f7696c507af5f38e24b662)

**ステップ 7。** 次の内容を入力してください **エンティティ ID** に設定し、 **ACS URL** Aikido に表示されるとおり。

![エンティティ ID と返信 URL のフィールドが指定された SAML SSO の設定画面。](/files/fd8c3f2a74c765dd0f588ce799366cbfd7aa1442)

**ステップ 8。** で **ステップ 2**に戻り、 **編集。**

![編集可能なオプションが強調表示されたユーザー属性とクレームのマッピング。](/files/c7f20337dd5ecdfd3b2414a95cf2a4592577ac7b)

**ステップ 9。** をクリックします **一意のユーザー識別子（Name ID）**。\
オプション: このページ上部の「新しいクレームを追加」をクリックすると、追加できます [カスタム属性](/docs/docs-ja/hajimeni/automated-user-management/saml-login/saml-user-rights-using-custom-attributes-advanced.md) を SAML に。詳細情報 [こちら](https://help.aikido.dev/doc/microsoft-azure-custom-attributes-with-saml--entra-id/docFaysVwVZy).

![強調表示された SAML クレーム: ユーザー識別用の一意のユーザー識別子（Name ID）。](/files/376c4e1ac5321189100771081ba1c402ff1d4544)

**ステップ 10。** 設定することを忘れないでください **ソース属性** を `user.mail` こちら。

![Azure AD で、ユーザーのメールを名前識別子として使う SAML クレームを構成しています。](/files/ad21adbd9972699e63a33a9a1bc47fe3880b261f)

**ステップ 11。** ステップ 3 では、次をダウンロードできます **証明書（Base64）** およびステップ 4 では次が表示されます **ログイン URL** に設定し、 **Microsoft Entra 識別子**。これらは Aikido にコピーして貼り付ける必要があります。

### Aikidoに戻る <a href="#go-back-to-aikido" id="go-back-to-aikido"></a>

* 次の内容を入力してください **Entity ID / Issuer** Azure の **Microsoft Entra 識別子**、そして **シングル サインオン URL** Azure の **ログイン URL** （どちらもステップ 11 から）、さらに **X.509証明書** Azure に表示されているとおり。
* また、 **会社ドメイン** も入力して、シングルサインオンURLなしで人々がログインできるようにしてください。

![シングル サインオン（SSO）認証情報を構成するための SAML 認証セットアップフォーム。](/files/0e38fd9a1ccaf3b189cbf5646e798a8cf4ff39cf)

> 成功です！ Azure の SAML アプリにアクセスできる人は、これから Aikido ワークスペースに自動参加できるようになります。

### SAMLクライアントを使用してユーザーがログインするための2つのオプション <a href="#id-2-options-for-users-to-login-using-your-saml-client" id="id-2-options-for-users-to-login-using-your-saml-client"></a>

**オプション1. SSOリンクを直接使用する**

ログインリンクをコピーし、他のユーザーと社内で共有してください。

![ログインリンクを管理またはコピーするためのオプションを含むSAML認証設定。](/files/3be45d87e9f29d5fe9157d43ff6f90932df80083)

**オプション2.** Aikidoのログイン画面に移動し、 **SSO経由でログイン** を選択して、メールアドレスを入力する **重要**：メールアドレスには、設定済みの会社ドメインが含まれている必要があります。

![Google、Microsoft、または SSO でワンクリックのログインとサインアップ。クレジットカードは不要です。](/files/5328eb6fc4a384e91130e9aa62cb5da8ef879f15)

![Google、Microsoft、またはメールでのサインイン オプションを提供するログイン画面。](/files/1769900b4df8ab61a95e97537eac3ce47254adfb)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/hajimeni/automated-user-management/saml-login/microsoft-azure-login-with-saml-entra-id.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
