Prerequisites
Tulip SAML integration is available for enterprise customers (see info about plans here: https://www.salto.io/pricing)
Contact support@salto.io in order to initialize the process.
Supported features
IdP-initiated SSO
SP-initiated SSO
Sign into Entra (Azure AD) admin dashboard (entra.microsoft.com)
Open Applications → Enterprise applications
Click on + New application
Give the app a name and select Integrate any other application you don’t find in the gallery (Non-gallery) and then click the Create button
Open Manage → Properties menu
You should see a screen similar to this, where you can upload Tulip logo from here
Go to Manage → Users and groups and assign relevant users to be able to use this application
Open Manage → Single sign-on and select SAML
Edit Step 1
Identifier should be:
urn:auth0:tulip:REPLACE_MEReply URL (Assertion Consumer Service URL) should be:
https://auth.salto.io/login/callback?connection=REPLACE_MEREPLACE_MEshould be replaced with the connection name you got from Tulip, or you can use your domain name with hyphens instead of dots, e.g.:
acme.com → acme-com
acme.co.uk → acme-co-uk
Edit Step 2
Set up the claims required for Tulip SAML integration
user.mail → emailuser.surname → family_nameuser.givenname → given_nameThe namespaces can be removed
It is recommended to verify that the Users that are going to use Tulip have valid values for these 3 fields
Send back to Tulip support:
Tulip support team will processes your request and notify you when it is ready
Your SAML configuration for Tulip is complete. You can start assigning users and groups to the application.
For IDP-initiated SSO, after clicking Tulip app in Entra ID "Apps Dashboard", you will be redirected to https://app.salto.io/
For SP-initiated SSO, navigate to https://app.salto.io/login, and enter the your email address:
Troubleshooting
If you encounter any issue during the process, or a generic access denied message after authenticating through Microsoft Entra ID, consult with Tulip support team (support@salto.io).
Please note, the Org Admin user in Tulip must invite other users to the org, otherwise when new users log in via SSO they will not be able to access the Tulip application.
See this article about inviting members for more information:












