Configure SAML

Configure Mobile Access Management to use SAML to provision and authenticate users against your Identity Provider, such as Microsoft Entra ID.

Depending on your organization, MAM takes the role of a Service Provider (SP) and you provide a system to serve as Identity Provider (IdP). No credentials are exchanged during the setup process. Instead, a trusted relationship is established between the services.

This authentication works to the MAM console and to the Launchpad app.

SAML keeps passwords internal to your network, making MAM more secure. SAML also leverages single sign-on, providing a better login experience for users.

The IdP is used only for user authentication. Authorization — assigning users to MAM roles — is still handled within the MAM console.

When a user launches MAM from their IdP, for example myapps.microsoft.com (Microsoft Entra ID), then the user will be generated at that time in MAM with the default role defined in the Admin settings.

  • There is only one default role for accounts automatically created this way, but a user’s role can be modified manually after the user is created.

  • To manually add new individual users and assign them to a specific role, go to the Team page.

  • When a user has no assigned role, they will see an error when attempting to log in with SAML.