Set up Azure Active Directory SAML SSO with Spendesk
Connect Microsoft Azure Active Directory (Azure AD) to Spendesk using SAML Single Sign-On (SSO) so your employees can log in with their existing company credentials. This guide walks you through creating and configuring the Spendesk application in Azure AD.
For: Account Owners and Azure Admins on plans with SAML SSO enabled.
Before you start
You need Owner access to the Enterprise Application in Azure AD to complete the configuration. Azure automatically assigns this role to the person who creates the application.
Spendesk is not listed as a gallery application in Azure AD. You must add it as a non-gallery (custom) application.
Each employee needs an email address, a first name, and a last name set up in Azure AD to be able to log in.
Spendesk does not support auto-provisioning or auto-deprovisioning (SCIM). Invite each user to Spendesk separately, in addition to adding them to the Azure application.
Step-by-step instructions
Open the Azure portal and sign in as an Azure admin or co-admin.
Navigate to Azure Active Directory > Enterprise Applications.
Click New application to start creating a new app.
Click Create your own application (also shown as "adding a non-gallery application").
Enter "Spendesk" as the application name.
Click Create.
Navigate to Single sign-on in the left menu.
Select SAML as the single sign-on method.
Click Edit in the "Basic SAML Configuration" section.
Enter the URL provided by Spendesk in the Identifier (Entity ID) field.
Enter the same URL provided by Spendesk in the Reply URL (Assertion Consumer Service URL) field.
Navigate to the User Attributes & Claims section.
Set the Unique User Identifier (Name ID) to user.mail.
Verify that the following claims are configured: user.mail, user.givenname, and user.surname.
Navigate to Users and groups and add each employee who needs SAML SSO access.
Return to the Single sign-on page and locate the SAML Signing Certificate section.
Download the Federation Metadata XML file.
Send the Federation Metadata XML file to your Spendesk CSM or account manager to finalize the setup.
Expected results
Once your Spendesk CSM confirms the setup is complete, your employees can sign in through the SAML SSO option on the Spendesk login page, or directly from their Azure AD application dashboard.
Troubleshooting
Symptom: New employees can't create Spendesk accounts, or SAML sends the wrong identifier (for example, userPrincipalName instead of an email address).
Cause: The Unique User Identifier in User Attributes & Claims is not set to user.mail.
Resolution: In Azure AD, go to Single sign-on > User Attributes & Claims and set the Unique User Identifier to user.mail. Confirm the user.givenname and user.surname claims are also present.
Symptom: A user clicks their Spendesk invite link and lands on an error page, or SAML SSO login fails for that user.
Cause: The user hasn't been added to the Spendesk application in Azure AD.
Resolution: Go to Enterprise Applications > Spendesk > Users and groups and assign the affected user or their group to the application.
Symptom: A user cannot log in via SAML SSO at all.
Cause: The user's Azure AD profile is missing an email address, first name, or last name.
Resolution: Ask your Azure admin to complete these fields on the user's Azure AD profile, then have the user try logging in again.
💡 Tip: Generate a Spendesk sign-up link for new employees so they can register without waiting for an individual invite. This works alongside your SAML SSO setup.
🔒 Access: SAML SSO is not enabled by default. Contact your Customer Success Manager to activate it on your account before configuring Azure AD.
⚠️ Warning: Spendesk doesn't support auto-provisioning or auto-deprovisioning (SCIM). Invite each employee to Spendesk directly, in addition to adding them to the Azure application.
