Identity: Microsoft Entra ID (Azure AD)

Identity: Microsoft Entra ID (Azure AD)

WAI Docs Wed Aug 19 13:22:37 EDT 2026
List
Quick Start
Welcome
Supported Applications & LLMs
Release Notes
August 18, 2026 WitnessAI Release
August 4, 2026 WitnessAI Release
July 21, 2026 WitnessAI Release
July 14, 2026 WitnessAI Release
July 9, 2026 WitnessAI Release
June 30, 2026 WitnessAI Hotfix
June 23, 2026 WitnessAI Release
June 16, 2026 WitnessAI Release
June 11, 2026 WitnessAI Release
June 4, 2026 WitnessAI Hotfix
June 2, 2026 WitnessAI Update
May 19, 2026 WitnessAI Update
April 30, 2026 WitnessAI Update
April 28, 2026 WitnessAI Update
April 23, 2026 WitnessAI Update
April 16, 2026 WitnessAI Update
April 14, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 9, 2026 WitnessAI Update
April 7, 2026 WitnessAI Update
April 2, 2026 WitnessAI Update
March 31, 2026 WitnessAI Update
March 24, 2026 WitnessAI Update
March 19, 2026 WitnessAI Update
March 17, 2026 WitnessAI Update
March 12, 2026 WitnessAI Update
March 5, 2026 WitnessAI Update
February 26, 2026 WitnessAI Update
February 24, 2026 WitnessAI Update
February 10, 2026 WitnessAI Update
January 27, 2026 WitnessAI Update
January 20, 2026 WitnessAI Update
January 13, 2026 WitnessAI Update
December 18, 2025 WitnessAI Update
December 9, 2025 WitnessAI Update
November 25, 2025 WitnessAI Update
November 18, 2025 WitnessAI Update
November 11, 2025 WitnessAI Update
October 28, 2025 WitnessAI Update
October 23, 2025 WitnessAI Update
October 9, 2025 WitnessAI Update
October 2, 2025 WitnessAI Update
September 30, 2025: WitnessAI Update
September 23, 2025: WitnessAI Update
August 12, 2025: WitnessAI Update
July 31, 2025: WitnessAI Update
July 18, 2025: WitnessAI Update
April 11, 2025: WitnessAI Release v2.0
June 9, 2025: WitnessAI Update
June 23, 2025: WitnessAI Update
TOC Left Sidebar: not active
TOC Left Sidebar: ORIGINAL
User Guide
Policies - GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
404
 

Microsoft Entra ID (Azure AD) Integration

Provide the account team with the IT Admin’s email address. An invitation will be sent to setup the Entra ID integration.
The email will come from onboarding_idp@witness.ai.
💡
Note: Entra ID SCIM integration is required for Witness Anywhere deployments. See the “SCIM Integration” section in this page below.
Once the IT Administrator receives the email to integrate Entra ID (Azure AD), click the link and select Entra ID (Azure AD)
notion image

Create Enterprise Application

  1. Select Enterprise applications from your Entra ID dashboard.
 
notion image
 
  1. Click New application and continue.
notion image
 
  1. Select Create your own application, then enter an App name that describes WitnessAI. Under What are you looking to do with your application?, select Integrate any other application you don’t find in the gallery (Non-gallery), then click Create.
notion image
 
  1. Next, select Single Sign-On from the Manage section in the left sidebar navigation menu, and then SAML.
  2. Continue with Basic SAML Configuration

Basic SAML Configuration

  1. Click the Edit icon in the top right of the first step
  2. notion image
     
    1. Copy this Identifier - replace customURI with your company’s URI.
    notion image
     
    b. Copy this Reply URL - replace customURI with your company’s URI.
    notion image
 
  1. Submit the Identifier and the Reply URL in the Basic SAML Configuration.
notion image
 

User Attributes & Claims

  1. Click the Edit icon in the top right of the second step.
notion image
 
 
  1. Fill in the following Attribute Statements by entering the claim name in the Name field and the value in the Source attribute field.
  2. Select Next:
    notion image
 
Below is an example of how to format your claim within the Azure claim editor.
Make sure the "Namespace" value ends in `/claims`
notion image
 
notion image

Assign People & Groups

  1. In order for your users and groups of users to be synced to WitnessAI you will need to assign them to your Entra ID SAML Application. Select Users and groups from the Manage section of the navigation menu.
notion image
 
  1. Select Add user/group from the top menu.
  2. notion image
 
  1. Select None selected under the Users and Groups. In the menu, select the users and groups of users that you want to add to the SAML application, and click Select.
  2. notion image
 
  1. Select Assign to add the selected users and groups of users to your SAML application.
  2. notion image
 

Upload IdP Metadata

  1. Navigate down to Section 3 of the Single Sign-On page, to SAML Signing Certificate.
  2. Copy the URL provided in App Federation Metadata URL.
    notion image
 
  1. Provide the Metadata URL you copied into the prompt as shown below:
  2. notion image
 

Test Single Sign-On

To activate Single Sign-On and verify that it was configured correctly you will need to perform a test sign-in with your identity provider
notion image

SCIM Integration

💡
Notes: Entra ID SCIM integration is required for Witness Anywhere deployments.
The SCIM API Tenant URL and Secret Token will be provided by the WitnessAI Account Team.

Add SCIM Provisioning

From your Microsoft Entra ID dashboard, navigate to Enterprise applications and select the WitnessAI application from the list.
notion image
 
Click Provisioning under the Manage section of the WitnessAI application.
notion image
Click Connect your application to begin configuring SCIM provisioning.
notion image

Edit & Test SCIM Connection

Enter the Tenant URL and Secret Token provided by the WitnessAI Account Team, then click Test connection. Once the connection is successfully validated, click Create to proceed.
notion image
 
Return to the WitnessAI Enterprise Application, click the Provisioning tab, expand the Mappings section, and select Provision Microsoft Entra ID Users.
notion image
 
Under Attribute Mappings, ensure that the userName attribute is mapped to the Entra ID attribute that contains the device username. Click Save after updating the attribute mappings.
Example: If the username on the device for the user john.doe@company.com is emp123, john, or john.doe, make sure the userName attribute is mapped to the Entra ID attribute that holds this corresponding value.
notion image
Note: You can identify the value of specific attributes by opening a user account in the Entra ID portal and clicking on Properties.
 
Return to the WitnessAI Enterprise Application, navigate to the Provisioning tab, set the Provisioning Status to On, and click Save.
notion image
Please allow up to one hour for the changes to sync from Entra ID to WitnessAI.