Setting up SSO between DocuSign and Microsoft Entra ID (Azure AD) takes about 30 to 45 minutes once you meet the prerequisites: a DocuSign Business Pro or higher plan, an admin in both systems, and a verified domain. In short: add the DocuSign gallery app in Entra ID, configure SAML, assign the users or groups, then enforce SSO at the domain level in DocuSign Admin. This guide walks through each step and covers the three tasks most guides miss — enforcing SSO-only login, automating provisioning with SCIM, and managing the SAML certificate before it expires. Confirm specifics against current DocuSign and Microsoft documentation.
Prerequisites for DocuSign SSO with Azure AD
Before you start, verify each requirement. The two most common reasons setups stall are the wrong plan and the wrong admin role.
If your team uses a lower DocuSign plan, SSO is gated behind an upgrade — the biggest cost surprise in this setup. Note that terminology changes over time: "Azure AD" is now "Microsoft Entra ID," and admin labels differ between DocuSign's classic and new experiences. For the broader security context, our guide on enabling two-factor authentication for signers explains how authentication layers combine.
Step-by-Step: Connect Azure AD to DocuSign
The integration is a standard SAML 2.0 setup. Microsoft's Entra gallery has a DocuSign app that fills in most SAML fields for you.
Step 1: Add DocuSign as an enterprise application in Entra ID. Sign in to the Microsoft Entra admin center, go to Identity > Applications > Enterprise applications, choose "New application," search the gallery for "DocuSign," and add it.
Step 2: Configure single sign-on (SAML). Open the app, select Single sign-on > SAML, and edit the basic SAML configuration. Set the Entity ID (Identifier) and Reply URL (Assertion Consumer Service) to the values DocuSign displays in its identity-provider settings page; copy them exactly.
Step 3: Download the signing certificate. Under SAML Certificates, download the certificate (Base64). DocuSign needs it when you register the identity provider.
Step 4: Register the IdP in DocuSign Admin. In DocuSign, go to Admin > Identity Providers (or Settings > Identity Provider Settings). Enable the identity provider, upload the certificate from step 3, and paste the Azure AD identifier and login URL from Entra's SAML page.
Step 5: Download DocuSign metadata. Download the metadata file from the same page and upload it into the Entra SAML configuration, or paste the identifier and reply URL manually.
Step 6: Assign users and groups. Back in Entra, open Users and groups and assign the users or groups that should sign in via SSO. Assignment is what actually grants access; SAML config alone is not enough.
Step 7: Test with a real account. Sign out, sign in with one test user through the SSO flow, and confirm the user lands in DocuSign without a password prompt. Then roll it out to the rest of the team.
Enforce SSO and Disable Password Login
Configuring SSO does not automatically disable passwords. Until you enforce SSO, users can still sign in with a DocuSign password, defeating the purpose of centralizing authentication.
In DocuSign Admin, go to the Domains section, open the settings for your verified domain, and require all users to log in with SSO only. Microsoft and DocuSign both recommend keeping a single administrative bypass account that can still log in with a password, so a certificate problem or IdP outage cannot lock you out. After enforcement, test both the bypass and normal flows before announcing the change.
Two enforcement details deserve attention:
- Multi-domain organizations. Enforcement applies per domain. Configure each domain and confirm which users map to it.
- New-user experience. With SSO enforced, users who have not yet been assigned in Entra cannot sign in. Pair enforcement with user assignment so onboarding is not blocked. For a security-mindful view of signer identity beyond SSO, see how Nota Sign integrates i-D One and i-Corp One for secure and compliant e-signing.
Automate User Provisioning with SCIM
SSO authenticates users; it does not create or deactivate them. Without provisioning, a new hire is manually added and a departing employee manually removed — forgotten removals are a classic insider-risk gap.
DocuSign added SCIM 2.0 provisioning for Microsoft Entra ID in 2025. With SCIM configured, Entra creates, updates, and deactivates DocuSign users automatically based on your group memberships. The setup requires the DocuSign Organization Management add-on, and provisioning runs user-level (group-level provisioning was still rolling out).
To enable it: in DocuSign Admin, generate a SCIM provisioning token for the directory integration; in Entra, add DocuSign as a provisioning-capable app, enable automatic provisioning, enter the SCIM endpoint and the token, and define attribute mappings (email, name, active status). After the first sync cycle, review the provisioning log to confirm users were created and deactivated as expected. Automatic deactivation on offboarding closes the lifecycle gap password hygiene alone cannot.
Manage the SAML Certificate
SAML certificates expire, and a quiet expiry is the classic SSO outage: users are locked out mid-morning with no obvious cause.
Two certificate clocks are in play:
- Microsoft side. For gallery apps, Entra ID issues the SAML signing certificate; custom SAML apps default to a short-lived certificate (Microsoft's standard is 90 days). Gallery apps can request a longer window. Set a reminder well before expiry.
- DocuSign side. Its documentation recommends a three-year certificate for identity-provider registration. To rotate it, download the new certificate, update the IdP settings, and confirm SSO still works before the old one expires.
DocuSign does not yet offer seamless multi-certificate rollover in every configuration, so rotation is a manual, coordinated change. Keep the old certificate until the new one is verified. For multi-year SSO operations, our explainer on the certificate of completion and audit trail shows what identity records a signing platform keeps.
Troubleshoot Common SSO Errors
Even a clean setup fails at some point. These are the failures that recur and how to fix them.
When you diagnose, rule out a known outage first, then check the two most common causes — identifier mismatch and expired certificates.
SSO, Security, and Compliance: Why It Matters
SSO is not a signing feature; it is an identity-control feature with four payoffs:
- One identity source. Signers and senders authenticate against Entra ID, so passwords stop living in a separate system.
- MFA and conditional access. Entra ID policies (multifactor authentication, device compliance, location-based access) apply to DocuSign automatically.
- Consolidated audit trail. Sign-in activity flows through Entra ID, so your security team sees DocuSign access alongside the rest of the environment.
- Faster offboarding. With SCIM, a terminated employee's access is revoked in one place instead of many.
For regional or industry compliance, our guides on eIDAS-compliant electronic signatures and whether electronic signatures are safe cover the baseline.
Nota Sign Keeps Identity Security Affordable for Small Teams
DocuSign ties SSO to Business Pro, so a small team pays the per-user price of the whole tier just to reach baseline identity controls. Nota Sign — FaDaDa's global e-signature platform — takes the opposite position: identity and access management are part of the platform rather than a paywall, and pricing does not climb as you add users.
Nota Sign has held the number-one spot in IDC's China e-signature software market rankings for consecutive years and enables legally valid signing in 100+ countries and regions. Its identity depth is the APAC-relevant part: support for Hong Kong's iAM Smart and Singapore's Singpass alongside SES/AES/QES signature levels, with regional data centers that respect residency rules. If SSO is security hygiene rather than a feature you want plan-level prices for, contact Nota Sign to compare identity requirements against what each platform charges.









