---
title: Azure AD Configuration
slug: kronpam-reference-guide-3-5-0/azure-ad-configuration
description: Learn how to set up a Kron PAM application for SAML SSO in Azure Active Directory with this comprehensive guide. Follow our step-by-step instructions to create the application, configure SAML settings, download and copy the SAML certificate, and establish
docTags: 
createdAt: 2022-12-23T08:42:59.000Z
---

Log in to Azure Active Directory with a user who has the required administrative rights and follow the below steps to create a Kron PAM application for SAML SSO.

1. New Application.
2. Create your<font color="#0c121d"> **Own**</font> application.
3. Give a name for Kron PAM.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/-8Dm0CS67MniYmxm71lmA_image.png" size="84" width="885" height="551" position="center" showCaption="false"}

- Go to the newly created Kron PAM Application.
- Choose **Single Sign-on** on the left pane.
- Choose **SAML**.
- Click edit for **Basic SAML Configuration**.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/WBIwbpMtJHTBzFoQWqNd2_image.png "Basic SAML Configuration")

- Enter the information below according to the Kron PAM Information.
- Note that the IP address of the Kron PAM app will change according to your environment.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/F5WVNR1ps0Jsr8f9ugVHB_im2.png" size="84" width="979" height="252" caption="Identifer" position="center" showCaption="true"}

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/B92vKSegnOW_BE6iTYoyC_im3.png" size="86" width="979" height="234" caption="Reply URL" position="center" showCaption="true"}

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/L6-Fsa1j0ADWCQgeSc-uh_im4.png" size="58" width="744" height="157" caption="Logout URL" position="center" showCaption="true"}

- Go to **Step 3&#x20;**&#x66;or SAML Certificates.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/TgiR7HQqldSufXHLH8gZJ_im5.png" size="84" width="739" height="365" caption="SAML Certificates" position="center" showCaption="true"}

Download the Certificate (Base 64) and open it via Notepad. Then copy it inside the notepad.&#x20;We will paste it to the SAML configuration on Kron PAM as SAML X509 Certf. Key

- Go to **Step 4** for Kron PAM Configurations.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/9ndYG8Dgly4BmDOn9gkTb_image.png "Set up Kron PAM ")

We will copy the above configurations and paste them as the Kron PAM SAML configuration. The logout URL in Azure will be pasted as the **Login Remote URL** in the SAML configuration. The Azure AD Identifier will be pasted as **SAML Entity ID in SAML** in the SAML configuration.

-  Go to Kron PAM **Properties**.

::Image[Copy the User access URL and paste it as the **SAML URL** in the Kron PAM SAML configuration.]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/Uzio1U7gcisyfhWf5tDzD_image.png" size="80" width="944" height="468" position="center" caption="Properties" showCaption="true"}

-  Finally, enter the Azure portal URL ([https://aad.portal.azure.com](https://aad.portal.azure.com)) as **the SAML Remote URL** in the SAML configuration in Kron PAM.

At the end of the configuration, the Singe Connect screen below will be displayed.

::Image[]{src="https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/9ag5rnB3RH24gTiAhLfoY_image.png" size="56" width="530" height="566" position="center" caption="SAML Config" showCaption="true"}

After setting to the required configurations, you need to edit **TomcatCorsFilter** in the tomcat configuration: Make an SSH to the Kron PAM server.

After setting the required configurations, you need to edit **TomcatCorsFilter** in the tomcat configuration: Make an SSH to the Kron PAM server

1. Open the web.xml file under the following directory.
   /u01/netright-tomcat/conf
2. Find TomcatCorsFilter part and add.

:::BlockQuote
\<filter-name>TomcatCorsFilter\</filter-name>\<filter-class>org.apache.catalina.filters.CorsFilter\</filter-class>                                                                      \<init-param>                                                                                                                                           \<param-name>cors.allowed.origins\</param-name>                                                          \<param-value>https\://login.microsoftonline.com\</param-value>                                                             \</init-param>
:::

- To test the SSO go to the application on Azure and click Single Sign-on on the left pane then go to step 5, and click the button **Test** button.

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/EWEMQjaU8yJDVOfpiajbB_image.png "Test")

A new, left side page will open to ask for the user who will log in to the application. If this user exists in the Kron PAM application, you will log in with no need for credentials.
