Official Canvas Document
|SIS||Student Information System|
This is what happens when a user isn't required to log in to a second service because information about the authenticated user is passed to the service.
To configure the integration of Canvas into Azure AD, you need to add Canvas from the gallery to your list of managed SaaS apps.
In the left navigation panel of the Azure portal, click Azure Active Directory icon.
Click the Enterprise applications, then click the All applications.
3. To add a new application, click the New application button on the top of the dialog.
4. In the search box, type Canvas. In the results panel, select Canvas and then click the Add button to add the application.
5. In the Canvas - Overview page of the Azure portal, click on Single Sign-on.
6. Click SAML.
7. On the SAML-based sign-on page, edit the Basic SAML Configuration section by clicking the pencil in the top-right corner.
8. Fill in the Identifier (Entity ID) fields with the http (not https) URLs of your production, test, and beta environments, followed by /saml2 (ie. http://your-institution.instructure.com/saml2 ).
In the Reply URL (Assertion Consumer Service URL) fields, add your Canvas domains (production, test, and beta) (ie. https://your-institution.instructure.com/* ). Examples below:
Here is an example if you use a normal Canvas domain:
Here is an example if you use a vanity URL with Canvas:
9. Edit the second section, User Attributes & Claims.
10. Click Unique User Identifier (Name ID) under required claim and change Source attribute to user.mail and click Save.
11. Click the Claim name ending in .../identity/claims/name to edit the entry.
12. Change the Source attribute to user.mail and click Save.
13. Click Properties. Change User assignment required to No. Click Save.
14. Return to the Single Sign-on screen. In the third section, copy the App Federation Metadata Url.
The following steps take place in Canvas.
15. In a new browser tab, log in to your Canvas instance as an administrator. From the Admin tile, click Authentication.
16. Click on the Choose an Authentication drop-down, then select the SAML option.
17. On the SAML configuration page, paste the App Federation Metadata Url into the IdP Metadata URI field. Click Save.
18. The page will reload with the values for IdP Entity ID, Log On URL, Log Out URL and Certificate Fingerprint automatically filled.
19. Test the configuration. Open a new incognito window, and go to
If successful, you’ll be prompted to enter your Microsoft email address, followed by your password. You will then be logged in and redirected to your Canvas instance.
Note that Canvas does not automatically create user accounts from successful single-sign-ons. User accounts must either be created manually in the web interface or through the SIS import CSVs.
20. Return to the Authentication screen. To make SAML the primary method for authentication, navigate to the bottom of the SAML section, and change Position to 1. Click Save.