Skip to main content
SSO is available on Enterprise plans, with your domains enabled by the Blinq team. Read How SAML SSO works first — it covers registering your domains, which has to happen before the SAML settings will open.
Blinq is listed in the Entra gallery, so you don’t need to build a custom application.

Add the Blinq application

1

Open Enterprise applications

Go to entra.microsoft.com or portal.azure.com and open Enterprise applications → New application.
2

Add Blinq

Search for Blinq, select it, then select Create.
3

Choose SAML

Open Single sign-on from the Manage menu, then select SAML.

Send Blinq’s details to Entra

In the Blinq dashboard, go to Settings → SAML and keep it open.
1

Edit the basic SAML configuration

In Entra, select Edit on the Basic SAML Configuration panel.
2

Paste the ACS URL

Copy the ACS URL from Blinq — it looks like auth.blinq.me/authorize/callback/… — and paste it into both Reply URL (Assertion Consumer Service URL) and Sign on URL. Save.

Set the signing option

This step is the most common cause of SSO failing later. If the signing option isn’t set correctly, sign-in fails with a signature error, and Entra has been known to reset it during tenant changes. Set it deliberately and re-check it if sign-in breaks.
1

Edit the SAML certificate

Select Edit on the SAML Certificates panel.
2

Choose the signing option

Set Signing Option to Sign SAML response and assertion, then save.

Send Entra’s details to Blinq

1

Download the certificate

From SAML Certificates, download the Base64 certificate, open it in a text editor, and paste the contents into Certificate in Blinq.
2

Copy the sign-on URL

Paste Entra’s Login URL into Single Sign-On URL in Blinq.
3

Copy the identifier

Paste the Microsoft Entra Identifier into Identity Provider Entity ID in Blinq.
4

Save

With every field filled in, select Save in Blinq.

Enforce SSO

Once you’ve confirmed a test sign-in works, switch on Enforce SSO for all users at the bottom of the SAML settings and save. Everyone signing in with an address on your registered domains is now routed through Entra ID. See How SAML SSO works for exactly what changes.
Don’t sign out of Blinq until a test sign-in has succeeded in another window. If enforcement is on and the configuration is wrong, only Blinq support can switch it back off.

Assigning people

Assign users or groups to the Blinq application under Users and groups, the same way you would for any enterprise application. If you also want accounts created and deactivated in Blinq automatically, see SCIM provisioning with Microsoft Entra ID — it uses the same application.

Need help?

For any questions or issues, contact Blinq support or email support@blinq.me.