# Azure Active Directory (AAD) App Gallery

### Create Azure AD Enterprise Application

Visit [Azure Marketplace](https://azuremarketplace.microsoft.com/marketplace/apps/aad.it-conductor?tab=Overview) to start using IT-Conductor AAD SSO:

{% hint style="info" %}
Make sure that the Azure domain is an exact match to the e-mail domain used to register a tenant in IT-Conductor. Users with mismatched email domains will not be able to auto-provision in IT-Conductor.
{% endhint %}

In the Azure portal, navigate to **Azure Active Directory** → **Enterprise Applications > New Application.**

Search for IT-Conductor and click on the application link.

<figure><img src="https://377464071-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXhp08OmU8050PePmMgDt%2Fuploads%2FsPFlc4oFvNgr5abAR0kz%2FAzure-add-ITC.png?alt=media&#x26;token=51477f4f-ada4-45a2-acdd-1f94ab810586" alt=""><figcaption><p>Figure 1: Browse Azure AD Gallery</p></figcaption></figure>

After Adding the application it will show up in the installed application list.

<figure><img src="https://377464071-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXhp08OmU8050PePmMgDt%2Fuploads%2F5PwIY2KHkDjlxPJ4TV9S%2FAzure-list-ITC.png?alt=media&#x26;token=27f42e16-e034-46c0-ab2b-cc999ba953ee" alt=""><figcaption><p>Figure 2: Enterprise Applications in Azure Portal</p></figcaption></figure>

Click on the application to finish the configuration.

<figure><img src="https://377464071-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXhp08OmU8050PePmMgDt%2Fuploads%2FexmEA8s3EgPN5LCIVyYF%2FAzure-edit-ITC.png?alt=media&#x26;token=76206b2e-ad61-4e4d-8b8c-919f3dfd5de5" alt=""><figcaption><p>Figure 3: IT-Conductor Overview in Azure Portal</p></figcaption></figure>

* Click on **Assign users and groups** to configure SSO application access.
* Click on **Set up single sign-on.**

<figure><img src="https://377464071-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FXhp08OmU8050PePmMgDt%2Fuploads%2FvDXWupsyBzuc78mGgeeQ%2FAzure-sso-ITC.png?alt=media&#x26;token=b364a3b6-2c94-4012-8cf0-ab15ee6e5f39" alt=""><figcaption><p>Figure 4: Set up SSO wil SAML</p></figcaption></figure>

Click **Federation Metadata XML Download** to export the metadata to a file

an Import the metadata into IT-Conductor to create an Identity Provider definition as described in [SSO Setup](https://docs.itconductor.com/user-guide/setup/sso-setup).

Click **Test** to validate SSO Configuration.
