Azure AD/ Entra ID SAML configuration (For Enterprise)
Set up Single Sign-On (SSO) for your team using Microsoft’s Azure Active Directory (AD)/ Entra ID.
This guide is for Canva Enterprise administrators and owners who will manage their team’s SSO settings. For Canva Education, go to Azure AD/ Entra ID SAML Configuration (For Education).
Step 1: Add Canva to Azure AD/ Entra ID
- From your Azure AD or Entra ID admin account, go to Microsoft Entra ID from the portal menu.
- Under Manage, select Enterprise applications.
- Click New application.
- In the search bar, enter Canva, then select it from the results list.
- Select Create to add the application.
- Select Set up single sign-on.
- Accept and save the single sign-on settings. The Identifier and Reply URL are pre-populated via the app and don't need to be updated.
- Optional: Under the Attributes & Claims section - the Claim names can be updated to the below for ease of understanding.
- In the SAML Signing Certificate section, click Edit, then select Base64 certificate download. You’ll need to copy and paste the certificate text into Canva later.
- Further down in the Set up Canva section, copy the following details. You’ll need them to complete the setup in Canva.
- Login URL
- Azure AD/ Entra ID Identifier
Step 2: Verify your domain
Changing your SSO domain? To prevent duplicate user accounts, contact our Support team before the domain change.
- Log in to your Canva account.
- Go to your profile avatar, then select Settings.
- From the side menu, select SSO and provisioning.
- Under Domain verification, select Add domain and enter your team’s domain.
- Click Submit domain. You will then be provided with a DNS token.
- Create a TXT record of the DNS token using your domain host. Help from your IT team might be needed for this step.
Learn more about adding a TXT record in our Setting up Single Sign-on (SSO) article.
Step 3: Set up SAML SSO in Canva
- Log in to your Canva account.
- Go to your profile avatar, then select Settings.
- From the side menu, select SSO and provisioning.
- Under Single sign-on (SSO), click Manage, then Edit IdP metadata.
- In the SSO or login URL field, paste your Login URL.
- In the Entity ID or Issuer URL field, paste your Azure AD/ Entra ID Identifier.
- In the X.509 public certificate field, paste all the contents from your SAML Signing Certificate - Base64 encoded (sample certificate).
- Click Save and next.
Step 4: Configure TeamId in Canva (optional if you are not a multi-team organization)
The value for the ‘TeamId’ will need to be mapped to each team in Canva and should be a unique value. The ‘TeamId’ value can be added/edited by an Organization Administrator.
What is TeamId and why is it important?
TeamId is a custom SAML attribute for multi-team organizations, indicating team membership. Canva adds users to specified teams if they're not already members but doesn't remove users based on this attribute.
The value for the ‘TeamId’ will need to be mapped to each team in Canva and should be a unique value. The ‘TeamId’ value can be added/edited by an Organization Administrator.
- Login as Organization admin.
- From the homepage, click your profile icon, then select Settings.
- Under Organization settings, go to Teams.
- Click More next to the team you want to edit.
- Select Edit Team Id.
- Enter a unique value for the TeamId and save your changes.
Step 5: Configure TeamId in Azure
Before proceeding, ensure:
- The TeamId is configured in Canva.
- The Canva application is added to Azure AD/Entra ID.
- Azure groups are assigned to the Canva application.
- In Azure AD/Entra ID, navigate to the Canva Enterprise Application > Single Sign-On > Attributes & Claims and click Edit.
- Once done, follow the steps below:
Option 1: Add TeamId as an Attribute
- Go into Claim conditions and set up a new attribute:
- UserType: Members
- Source: Attribute
- Value: Group name or identifier
- Assign groups for each condition and save.
You can scope multiple groups per condition. If you have multiple groups that you need to be going into the same Canva team, select all of them within that condition.
This will only send 1 teamId for a user. If a user is in multiple teams, multiple teamIds won’t be sent.
Option 2: Use Group Claims
This group needs to contain all the users in the org and be the only group sent as part of the claim.
1. Add a Group Claim and name it TeamId.2. Configure group claims following Azure Active Directory guidelines.
Option 3: Use an Existing Unique Attribute
If you have an attribute in your SAML app with any unique identifier related to the org, you can use that as your “TeamId” attribute to send information on what team each user should belong to.
- Add a claim and name it TeamId.
- Set the Source Attribute to an existing unique identifier.
Step 6: Test your SSO login experience
There are two easy ways to test your setup:
Option 1: Use the Test SSO button
- Go to your profile avatar, then select Settings.
- From the side menu, select SSO and provisioning tab.
- Under Single sign-on (SSO), select Manage, then Test SSO.
Option 2: Log out and test SSO login
- Go to SSO and provisioning, then select Single sign-on (SSO)
- Click Manage then select Configure SSO settings.
- Set the SSO settings option to Optional for everyone.
- Log out of your Canva account.
- On the login page, select Continue with email, then Log in with SSO.
If you were redirected to your team’s account, you have successfully configured SSO!
Step 7: Set up login and signup controls
Choose how you want people to log in to your SSO-managed teams.
- Go to your profile avatar, then select Settings.
- From the side menu, select SSO and provisioning.
- Select Single sign-on (SSO), then Manage, then Configure SSO settings.
- Choose your preferred SSO setting. Learn more about each option in Setting up login and signup controls.
- Click Save Connection
If you’re having trouble setting up SSO, check our Troubleshooting SSO errors article.
Was this helpful?
Helpful
Unhelpful