Skip to content
  • There are no suggestions because the search field is empty.

Set Up Single Sign-On (SSO) with Azure AD/Entra

Admin Portal


Note: This feature is available to Enterprise customers, as well as customers on the PDF Plus, Sign Plus, or higher plans.



Your account must have a verified domain in order to set up and enable SSO. Review this article for instructions on verifying your domain. Review this article for instructions on verifying your domain.

Step 1: Create a new application on Entra ID

  1. Log in to the Microsoft Azure Portal

  2. Go to Microsoft Entra ID

  3. Navigate to Enterprise applications > All applications.

  4. Add Nitro Productivity Suite application

  5. Navigate to SAML SSO section on Nitro Productivity Pro

    1. Enter the following placeholder values:

      1. SAML Entity ID:urn:auth0:gonitro-prod:123

      2. ACS URL: https://gonitro-prod.eu.auth0.com/login/callback?connection=123
        These will be updated later in Step 3.

  6. Download the Base 64 Cert from Box 3.

  7. Copy Login URL from Box 4.

Step 2: Set Up SAML SSO in the Nitro Admin Portal

  1. Log in to the Nitro Admin Portal

  2. From the left navigation pane, go to Settings, then navigate to the Single Sign-On tab.

  3. Click the Edit Configuration button.

    Image 1-1
  4. Paste the Login URL copied from Entra into the Sign-in URL field.

  5. Upload the Base 64 Cert downloaded from Entra into the X.509 Signing Certificate field

    Image 2-1

  6. Click Submit and Enable SSO, then click Save.
    Image 3-1
  7. Copy the following values for use in the next step:

    • Entity ID

    • Reply URL 1

    • Reply URL 2

Step 3: Update SAML Settings in Entra

  1. Go back to Microsoft Entra ID

    Update Entra Step 2

  2. Navigate to Enterprise applications > All applications > Nitro Productivity Suite

    Image 2
  3. Under the Manage menu, click Single sign-on.

  4. Click Edit on Basic SAML Configuration

    Image 3

  5. Update the placeholder values using the values copied from Nitro Admin:

    1. Paste SAML Entity ID to Identifier (Entity ID)

    2. Paste both Reply URL 1 and Reply URL 2 to under Reply URL (Assertion Consumer Service URL)

      For each Reply URL, create two entries in the ACS URL section:

      You should end up with 4 total ACS URLs:

      1. Reply URL #1 (with the connection parameter)

      2. Reply URL #1 (without the connection parameter)

      3. Reply URL #2 (with the connection parameter)

      4. Reply URL #2 (without the connection parameter)

      Image 5
  6. Save Changes