Prerequisites
Before configuring SSO, ensure you have:- Administrative access to Microsoft Entra ID
- Administrative access to your Beam workspace
- Access to your organization’s Azure tenant
Configure Azure Entra ID
Go to Microsoft Entra ID
On left Side bar you will see Enterprise Application open it

Now click on a new application

Click on Create your own Application on side bar select option 3 and set application name

Now application is created click on option 2. Set up single sign on

Now open single sign on from the left bar and choose SAML

Now edit basic SAML Configuration

Add these attributes and claims

Download Federation Metadata XML and follow step 11

Configure Beam Platform
Now go to app.beam.ai login into it open workspace settings from top left and click on SSO and do these entries and upload XML file
Testing Your SSO Setup
After configuration, test the SSO integration:Test User Login
Verify User Profile
Troubleshooting
SSO login fails with 'Application not approved'
SSO login fails with 'Application not approved'
- Have an Azure administrator locate the Beam application in the Enterprise Applications list
- Grant necessary permissions for the application
- Ensure users or groups are assigned to the application
- Verify the application is not blocked by Conditional Access policies
User attributes not mapping correctly
User attributes not mapping correctly
- Verify the attribute mappings in Azure match exactly
- Check that source attributes are available in user profiles
- Re-download and re-upload the Federation Metadata XML file
- Contact Beam support if issues persist
'Sign in with SSO' button not appearing
'Sign in with SSO' button not appearing
Users can't access Beam after Azure authentication
Users can't access Beam after Azure authentication
- Ensure users are invited to the Beam workspace
- Check user role assignments in workspace settings
- Verify email addresses match between Azure and Beam invitations
- Have users check spam/junk folders for invitation emails