{"id":68055,"date":"2025-09-22T12:25:54","date_gmt":"2025-09-22T06:55:54","guid":{"rendered":"https:\/\/www.tothenew.com\/blog\/?p=68055"},"modified":"2026-09-01T15:51:52","modified_gmt":"2026-09-01T10:21:52","slug":"step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad","status":"publish","type":"post","link":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/","title":{"rendered":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform."},"content":{"rendered":"<h3><strong>1. Introduction<\/strong><\/h3>\n<p>The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol to exchange authentication and authorization data between identity providers (IdPs) like Microsoft Entra ID (formerly Azure AD).or <strong>Okta<\/strong>, and service providers (SPs) such as <strong>AEM, Salesforce<\/strong>, or other business applications.<\/p>\n<h3><strong>2. Prerequisites<\/strong><\/h3>\n<p>To get started, you need the following components:<\/p>\n<h4><strong>\u00a02.1 Azure:<\/strong><\/h4>\n<ul style=\"list-style-type: square;\">\n<li>Azure Subscription<\/li>\n<li>Azure AD SAML Signing Certificate<\/li>\n<li>Azure AD Login URL<\/li>\n<li>Azure AD Logout URL<\/li>\n<li>Azure AD Identifier (Entity ID)<\/li>\n<li>App Federation Metadata URL<\/li>\n<\/ul>\n<h4><strong>2.2 AEM :<\/strong><\/h4>\n<ul style=\"list-style-type: square;\">\n<li>AEM 6.x Author or Publish instance enabled over SSL using TLS1.1 or above<\/li>\n<li>AEM Package Manager console<\/li>\n<li>AEM OSGi Access<\/li>\n<li>Deployment Pipeline access to deploy\/update the Dispatcher changes.<\/li>\n<\/ul>\n<h3><strong>3. Configuration changes in the Azure<\/strong><\/h3>\n<ol>\n<li>Create Application named <strong>Adobe Experience Manager <\/strong>in Azure portal.<\/li>\n<li>Access Azure Portal &#8211; <a href=\"http:\/\/portal.azure.com\/\">portal.azure.com.<\/a><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74526\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/1.1.png\" alt=\"txt\" width=\"2578\" height=\"830\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/1.1.png 2578w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-300x97.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-1024x330.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-768x247.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-1536x495.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-2048x659.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/1.1-624x201.png 624w\" sizes=\"auto, (max-width: 2578px) 100vw, 2578px\" \/><\/li>\n<li>Look for &#8220;Microsoft Entra ID&#8221; service \u2192 Click &#8220;<strong>+<\/strong>&#8221;\u00a0 \u2192\u00a0select &#8220;<strong>Enterprise applications<\/strong>&#8220;.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74527\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/2.png\" alt=\"txt\" width=\"2564\" height=\"1154\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/2.png 2564w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-300x135.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-1024x461.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-768x346.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-1536x691.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-2048x922.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/2-624x281.png 624w\" sizes=\"auto, (max-width: 2564px) 100vw, 2564px\" \/><\/li>\n<li>From gallery section, type <span style=\"text-decoration: underline;\">Adobe Experience Manager<\/span> in the search box.<\/li>\n<li>Select Adobe Experience Manager from results panel and then add the application. <strong>Wait a few seconds<\/strong> while the app is added to your tenant.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74570\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM.png\" alt=\"txt\" width=\"3456\" height=\"1884\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM.png 3456w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-300x164.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-1024x558.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-768x419.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-1536x837.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-2048x1116.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.28.35\u202fAM-624x340.png 624w\" sizes=\"auto, (max-width: 3456px) 100vw, 3456px\" \/><\/li>\n<li>Once the application created \u2192 Adobe Experience Manager \u2192 Manage \u2192 select &#8220;<strong>Single sign-on<\/strong>&#8221; \u2192 &#8220;<strong>SAML<\/strong>&#8220;<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74571\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM.png\" alt=\"txt\" width=\"3000\" height=\"1494\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM.png 3000w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-300x149.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-1024x510.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-768x382.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-1536x765.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-2048x1020.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.32.27\u202fAM-624x311.png 624w\" sizes=\"auto, (max-width: 3000px) 100vw, 3000px\" \/><\/li>\n<li>Click on <span style=\"text-decoration: underline;\">pencil icon<\/span> to edit the\u00a0<strong>Basic SAML Configuration<\/strong><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74572\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM.png\" alt=\"txt\" width=\"2734\" height=\"1938\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM.png 2734w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-300x213.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-1024x726.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-768x544.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-1536x1089.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-2048x1452.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.34.38\u202fAM-624x442.png 624w\" sizes=\"auto, (max-width: 2734px) 100vw, 2734px\" \/><\/li>\n<li>On the Basic SAML Configuration section, if you wish to configure the application in <strong>IDP initiated mode<\/strong>, enter the values for the following fields:<\/li>\n<li>In the <strong>Identifier text box<\/strong>, type a unique value that you define on your <strong>AEM server<\/strong>.<\/li>\n<li>In the <strong>Reply URL text box<\/strong>, type a <strong>URL<\/strong> using the following pattern: <span style=\"text-decoration: underline;\">https:\/\/&lt;AEM Server Url&gt;\/saml_login<\/span> .<\/li>\n<li>In the <strong>Sign-on URL text box<\/strong> should be configured for the application in SP initiated mode. <img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74573\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM.png\" alt=\"txt\" width=\"3282\" height=\"1902\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM.png 3282w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-300x174.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-1024x593.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-768x445.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-1536x890.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-2048x1187.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.39.38\u202fAM-624x362.png 624w\" sizes=\"auto, (max-width: 3282px) 100vw, 3282px\" \/><\/li>\n<li>On samepage, in the <strong>SAML Signing Certificate<\/strong> section, click <span style=\"text-decoration: underline;\">Download<\/span> to download the <strong>Certificate (Base64)<\/strong> from the given options as per your requirement and save it on your computer (<span style=\"text-decoration: underline;\">this certificate can be used in AEM configuration<\/span>)<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74574\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM.png\" alt=\"txt\" width=\"1558\" height=\"1678\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM.png 1558w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM-279x300.png 279w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM-951x1024.png 951w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM-768x827.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM-1426x1536.png 1426w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.45.08\u202fAM-624x672.png 624w\" sizes=\"auto, (max-width: 1558px) 100vw, 1558px\" \/><\/li>\n<li>On the <strong>Set up Adobe Experience Manager section<\/strong>, copy the appropriate URL(s) as per your requirement. <strong>Login URL<\/strong> should be used in the AEM SAML Configuration (section 4.4)<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74575\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM.png\" alt=\"txt\" width=\"1542\" height=\"1430\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM.png 1542w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM-300x278.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM-1024x950.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM-768x712.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM-1536x1424.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.50.31\u202fAM-624x579.png 624w\" sizes=\"auto, (max-width: 1542px) 100vw, 1542px\" \/><\/li>\n<\/ol>\n<h3><strong>3.1 Create a Microsoft Entra user to test the flow:<\/strong><\/h3>\n<p>In this section, you will create a test user called &#8220;<strong>Test User<\/strong>&#8221;<\/p>\n<ol>\n<li>Look for &#8220;Microsoft Entra ID&#8221; service \u2192 Click Add &#8220;+&#8221;\u00a0 \u2192\u00a0<strong>Users<\/strong> \u2192 Create User<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74576\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM.png\" alt=\"txt\" width=\"2712\" height=\"804\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM.png 2712w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-300x89.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-1024x304.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-768x228.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-1536x455.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-2048x607.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-6.52.58\u202fAM-624x185.png 624w\" sizes=\"auto, (max-width: 2712px) 100vw, 2712px\" \/><\/li>\n<li>In the Display name field, enter <strong>test.user<\/strong>.<\/li>\n<li>In the User principal name field, enter the username@companydomain.extension. For example, <strong>test.user@test.com<\/strong>.<\/li>\n<li>Setup the password and Select <strong>Review + Create<\/strong>.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74577\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM.png\" alt=\"txt\" width=\"1438\" height=\"1900\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM.png 1438w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM-227x300.png 227w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM-775x1024.png 775w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM-768x1015.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM-1163x1536.png 1163w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.00.46\u202fAM-624x824.png 624w\" sizes=\"auto, (max-width: 1438px) 100vw, 1438px\" \/><\/li>\n<\/ol>\n<p style=\"text-align: left;\">In this section, you&#8217;ll enable <strong>test.user<\/strong> to use single sign-on by granting access to Adobe Experience Manager application.<\/p>\n<ol>\n<li>Navigate to application overview page, select <strong>Users and groups<\/strong>.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74578\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM.png\" alt=\"txt\" width=\"2180\" height=\"1362\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM.png 2180w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-300x187.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-1024x640.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-768x480.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-1536x960.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-2048x1280.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.06.42\u202fAM-624x390.png 624w\" sizes=\"auto, (max-width: 2180px) 100vw, 2180px\" \/><\/li>\n<li>Select <strong>Add user\/group<\/strong>, then select Users and groups in the <strong>Add Assignment dialog<\/strong>.<\/li>\n<li>In the Users and groups dialog, select <strong>test.user<\/strong> from the Users list, then click the <strong>Select<\/strong> button at the bottom of the screen.<\/li>\n<li>If you are expecting a role to be assigned to the users, you can select it from the Select a role dropdown. If no role has been set up for this app, you see &#8220;<strong>Default Access<\/strong>&#8221; role selected.<\/li>\n<li>In the Add Assignment dialog, click the <strong>Assign<\/strong> button.<\/li>\n<\/ol>\n<h3><strong>4. Configuration changes in the AEM side<\/strong><\/h3>\n<h4><strong>4.1 Create Trust Store Certificate:<\/strong><\/h4>\n<ol>\n<li>Login to <strong>AEM instance<\/strong><\/li>\n<li>Navigate to Tools \u2192 Security \u2192 <strong>Trust Store \u2192 <\/strong>https:\/\/&lt;IP address&gt;\/libs\/granite\/security\/content\/truststore.html.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74468\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM.png\" alt=\"Truststore password\" width=\"1650\" height=\"1214\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM.png 1650w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM-300x221.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM-1024x753.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM-768x565.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM-1536x1130.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.20.13\u202fPM-624x459.png 624w\" sizes=\"auto, (max-width: 1650px) 100vw, 1650px\" \/><\/li>\n<li>Click on &#8220;<strong>Trust Store<\/strong>&#8220;<\/li>\n<li>Click the empty box titled &#8220;<strong>Add Certificate from CER file<\/strong>&#8221; and upload the downloaded <strong>Azure certificate<\/strong>.<\/li>\n<li>Make sure the &#8220;<span style=\"text-decoration: underline;\">Map Certificate to User<\/span>&#8221; text box remains <span style=\"text-decoration: underline;\">empty<\/span>.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74476\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/azure-cert.png\" alt=\"Upload Azure Certificate\" width=\"3450\" height=\"880\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/azure-cert.png 3450w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-300x77.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-1024x261.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-768x196.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-1536x392.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-2048x522.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/azure-cert-624x159.png 624w\" sizes=\"auto, (max-width: 3450px) 100vw, 3450px\" \/>Copy the <strong>Cert Alias name<\/strong> where it should be configured in the <span style=\"text-decoration: underline;\">AEM SAML configuration<\/span>.<\/li>\n<\/ol>\n<h4><strong>4.2 Generate AEM Keys and Certificate:<\/strong><\/h4>\n<p>Generate and configure the AEM key pair (<span style=\"text-decoration: underline;\">public and private<\/span>). In Azure AD, the private key is used to sign SAML messages, whereas the public key (certificate) is used to encrypt the message and validate the signatures. AEM (the SP) uses its private key to sign the AuthnRequest and Azure uses AEM&#8217;s public certificate to encrypt assertions returned to AEM.<\/p>\n<p>AEM setup requires a private key in <strong>PKCS8 format<\/strong>. Generate RSA private and public keys, plus a certificate. To accomplish this, execute the following command and complete the form.<\/p>\n<p><span style=\"text-decoration: underline;\">Define a PEM pass phrase while generating the key (<\/span>execute the bold highlighted openssl commands<span style=\"text-decoration: underline;\">)<\/span><\/p>\n<p><strong>openssl req -x509 -sha256 -days 365 -newkey rsa:4096 -keyout aem.key -out aem.crt<\/strong><\/p>\n<p><span style=\"text-decoration: underline;\">Convert PEM into DER format. Enter the PEM pass phrase created in above step to write into RSA key<\/span><\/p>\n<p><strong>openssl rsa -in aem.key -outformat der -out aem.der<\/strong><\/p>\n<p><span style=\"text-decoration: underline;\">The DER key for PKCS8 must be nocrypt; otherwise, AEM gives an error when inserting the DER key<\/span><\/p>\n<p><strong>openssl pkcs8 -topk8 -inform der -nocrypt -in aem.der -outform der -out aem-pkcs8.der<\/strong><\/p>\n<p>You should now have-<\/p>\n<p>\u251c\u2500\u2500 aem-pkcs8.der<\/p>\n<p>\u251c\u2500\u2500 aem.crt<\/p>\n<p>\u251c\u2500\u2500 aem.der<\/p>\n<p>\u2514\u2500\u2500 aem.key<\/p>\n<h4><strong>4.3 Create Keystore for authentication-service user:<\/strong><\/h4>\n<ol>\n<li>Login to the AEM instance.<\/li>\n<li>Go to Tools \u2192 Security \u2192 Users<\/li>\n<li>Search for &#8220;<strong>authentication-service<\/strong>&#8221; \u2192 Click on Keystore.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74487\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM.png\" alt=\"authentication-service user\" width=\"1956\" height=\"744\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM.png 1956w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM-300x114.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM-1024x389.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM-768x292.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM-1536x584.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.52.47\u202fPM-624x237.png 624w\" sizes=\"auto, (max-width: 1956px) 100vw, 1956px\" \/><\/li>\n<li>Create a <strong>keystore<\/strong> password (this password should be used in SAML configuration <span style=\"text-decoration: underline;\">section 4.4 <\/span>)<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74489\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM.png\" alt=\"Create Keystore Password\" width=\"1266\" height=\"1190\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM.png 1266w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM-300x282.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM-1024x963.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM-768x722.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM-624x587.png 624w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.46.50\u202fPM-24x24.png 24w\" sizes=\"auto, (max-width: 1266px) 100vw, 1266px\" \/><\/li>\n<li>On the new pop-up box, enter the alias name, upload the &#8220;<strong>aem-pkcs8.der<\/strong>&#8221; certificate in the Private key area, and upload &#8220;<strong>aem.crt<\/strong>&#8221;\u00a0 and then click <strong>Submit<\/strong>.<img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74493\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM.png\" alt=\"Update key details\" width=\"3442\" height=\"1018\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM.png 3442w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-300x89.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-1024x303.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-768x227.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-1536x454.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-2048x606.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.52.06\u202fPM-624x185.png 624w\" sizes=\"auto, (max-width: 3442px) 100vw, 3442px\" \/><\/li>\n<li>We would need the <strong>Alias name<\/strong>, <strong>keystore password<\/strong> to be configured in the AEM SAML configuration.<\/li>\n<\/ol>\n<h4><strong>4.4 Configure AEM SAML:<\/strong><\/h4>\n<p>Search&#8221;<span style=\"text-decoration: underline;\">Adobe Granite SAML 2.0 Authentication Handler<\/span>&#8221; configuration and create a new configuration by selecting the &#8220;<strong>+<\/strong>&#8221; button and then update the following properties:<\/p>\n<p>Consider that we are enabling SSO authentication for the path \/<strong>content\/brandportal<\/strong>. Enabling SSO on a <span style=\"text-decoration: underline;\">specific page<\/span> is also feasible.<\/p>\n<ol>\n<li><strong>path<\/strong> &#8211; Configure the specific content paths that the SAML handler should listen for and redirect to the SSO login page. When we configure &#8220;\/&#8221; SSO authentication, it applies to all content paths in the AEM repository.<\/li>\n<li><strong>IDP URL<\/strong> &#8211; Enter the <strong>Azure AD Login URL<\/strong> value from Step 13 of <span style=\"text-decoration: underline;\">section 3 &#8211; Configuration changes in the Azure<\/span>.<\/li>\n<li><strong>IDP Certificate Alias &#8211; <\/strong>Enter the\u00a0Certificate Alias\u00a0value that you added in <strong>TrustStore.<\/strong><\/li>\n<li><strong>Service Provider Entity ID<\/strong> &#8211; Enter the <strong>endpoint URL<\/strong> that users can access (Entity ID).<\/li>\n<li><strong>Assertion Consumer Service URL<\/strong> &#8211; Enter the <strong>Reply URL<\/strong> value that you configured in the section 3. including the content path that ends with saml_login.<\/li>\n<li><strong>SP Private Key Alias<\/strong> &#8211; Alias name defined in the <strong>Authenticate-user keystore<\/strong> setup.<\/li>\n<li><strong>Password of Key Store<\/strong> &#8211; The key store password defined in the <strong>Authenticate-user keystore setup<\/strong> (keystore password created in this section &#8211; 4.3)<\/li>\n<li><strong>Use Encryption<\/strong> &#8211; Initially complete SAML setup <strong>without encryption<\/strong> and re-enable once flow is working. Using this way, it is easy to debug the issue.<\/li>\n<li><strong>Auto create CRX Users<\/strong> \u2014 Keeping it checked will create a user in AEM using the User ID attribute specified above.<\/li>\n<li>Logout URL (Optional) &#8211; Azure AD Logout URL<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74466\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM.png\" alt=\"Adobe Granite SAML 2.0 Authentication Handler\" width=\"3138\" height=\"1716\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM.png 3138w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-300x164.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-1024x560.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-768x420.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-1536x840.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-2048x1120.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-2.04.31\u202fPM-624x341.png 624w\" sizes=\"auto, (max-width: 3138px) 100vw, 3138px\" \/><\/p>\n<h4><strong>4.5 Apache Sling Referrer Filter :<\/strong><\/h4>\n<p>Search for Apache \u201c<span style=\"text-decoration: underline;\">Sling Referrer Filter<\/span>\u201d configuration and update the below settings:<\/p>\n<ol>\n<li>Ensure <strong>allow.empty<\/strong> value is set to <strong>true<\/strong>.<\/li>\n<li>Add &#8220;<strong>login.microsoftonline.com<\/strong>&#8221; to the Allow Hosts.<\/li>\n<li>Click <strong>Save<\/strong><\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-81963\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM.png\" alt=\"Apache Sling Referrer Filter\" width=\"3114\" height=\"988\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM.png 3114w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-300x95.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-1024x325.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-768x244.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-1536x487.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-2048x650.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2026\/09\/Screenshot-2026-09-01-at-12.24.03\u202fPM-624x198.png 624w\" sizes=\"auto, (max-width: 3114px) 100vw, 3114px\" \/><\/p>\n<p><strong style=\"font-size: 1rem;\">4.6 Apache Sling Authentication Service:<\/strong><\/p>\n<ol>\n<li>Allow <strong>Anonymous<\/strong> Access to be allowed <span style=\"text-decoration: underline;\">if SSO is only enabled for the Publish instance<\/span>.<\/li>\n<li>Update the content path to enable SSO authentication for a specified path.<\/li>\n<li>Save the configuration.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74464\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM.png\" alt=\"Apache Sling Authentication Service\" width=\"3102\" height=\"1354\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM.png 3102w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-300x131.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-1024x447.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-768x335.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-1536x670.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-2048x894.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-29-at-1.43.57\u202fPM-624x272.png 624w\" sizes=\"auto, (max-width: 3102px) 100vw, 3102px\" \/><\/p>\n<p><strong>5. Configure the following rules in the specific site filter file of the Dispatcher configuration:<\/strong><\/p>\n<p>Append following rules in the filter section of your dispatcher:<\/p>\n<p>\/0200 { \/type &#8220;allow&#8221; \/method &#8220;POST&#8221; \/url &#8220;*\/saml_login&#8221; }<br \/>\n\/0201 { \/type &#8220;allow&#8221; \/method &#8220;GET&#8221; \/url &#8220;\/system\/sling\/logout&#8221; }<br \/>\n\/0202 { \/type &#8220;allow&#8221; \/method &#8220;GET&#8221; \/url &#8220;\/system\/sling\/login&#8221; }<\/p>\n<p><strong>6. Test SSO<\/strong><\/p>\n<p>Make sure the ACL url and Dispatcher Filter rules are appropriately defined; otherwise, we may notice a 500 error after login and a blocked error in the dispatcher logs.<\/p>\n<ol>\n<li>Click on \u201c<strong>Test this application<\/strong>\u201d on the Azure SSO configuration page , this will redirect to Adobe Experience Manager Sign-on URL,\u00a0which you set up the SSO<\/li>\n<li>Access the AEM Endpoint URL to see if it redirects to the SAML authentication screen and then complete the flow.<\/li>\n<\/ol>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74579\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM.png\" alt=\"txt\" width=\"2414\" height=\"1854\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM.png 2414w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-300x230.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-1024x786.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-768x590.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-1536x1180.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-2048x1573.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.18.13\u202fAM-624x479.png 624w\" sizes=\"auto, (max-width: 2414px) 100vw, 2414px\" \/><\/p>\n<p><strong>7. Troubleshooting Steps<\/strong><\/p>\n<p>Navigate to Activity tab to check the Audit log and Sign-in logs to triage the user login issues.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-74580\" src=\"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM.png\" alt=\"txt\" width=\"2308\" height=\"1744\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM.png 2308w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-300x227.png 300w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-1024x774.png 1024w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-768x580.png 768w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-1536x1161.png 1536w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-2048x1548.png 2048w, https:\/\/www.tothenew.com\/blog\/wp-content\/uploads\/2025\/08\/Screenshot-2025-08-30-at-7.17.17\u202fAM-624x472.png 624w\" sizes=\"auto, (max-width: 2308px) 100vw, 2308px\" \/><\/p>\n<p><strong>Common Issues observed<\/strong><\/p>\n<p><strong>Error:<\/strong> com.adobe.granite.auth.saml.model.Assertion Invalid Assertion: Signature invalid.com.adobe.granite.auth.saml.SamlAuthenticationHandler Private key of SP not provided: Cannot sign Authn request<\/p>\n<p><strong>Solution<\/strong>: Delete and re-upload the truststore certificates (<strong>.pem<\/strong>) and keystore private keys (<strong>aem-pkcs8.der and aem.crt<\/strong>).<\/p>\n<p><strong>Error: \/<\/strong>libs\/granite\/core\/content\/login.error?j_reason=user_not_found on console. com.adobe.granite.auth.saml.extidp.DefaultUserSync User synchronisation failed. Could not access the repository.<\/p>\n<p><strong>Solution: <\/strong>Enable Auto-Create User in the AEM SAML.<\/p>\n<p><strong>Error: <\/strong>Identifier Not Found:<\/p>\n<p><strong>Solution: <\/strong>Configured Identifier name in the Azure Basic SAML configuration is not matching with Service Provider Entity ID in AEM SAML configuration.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol [&hellip;]<\/p>\n","protected":false},"author":1545,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":1,"footnotes":""},"categories":[5868],"tags":[5314,8796,4847,7901,7902,8792,8791,8797,7900,7903,7472,2895,8793,8795,8790,8794],"class_list":["post-68055","post","type-post","status-publish","format-standard","hentry","category-adobe","tag-adobeexperiencemanager","tag-adobegranitesaml","tag-aem","tag-aemsamlauthenticationusingmicrosoftazuread","tag-aemsamlsso","tag-aemsso","tag-azureactivedirectory","tag-azureadsso","tag-integratesamlwithsso","tag-microsoftazuread","tag-microsoftentraid","tag-saml","tag-samlauthentication","tag-samlintegration","tag-samlsso","tag-singlesignon"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Raja Karuppusamy\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"TO THE NEW BLOG\" \/>\n\t\t<meta property=\"og:type\" content=\"blog\" \/>\n\t\t<meta property=\"og:title\" content=\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog\" \/>\n\t\t<meta property=\"og:description\" content=\"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@tothenew\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog\" \/>\n\t\t<meta name=\"twitter:description\" content=\"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#article\",\"name\":\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\\\/AMS platform. | TO THE NEW Blog\",\"headline\":\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\\\/AMS platform.\",\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/raja-karuppusamy\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/wp-ttn-blog\\\/uploads\\\/2025\\\/08\\\/1.1.png\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#articleImage\"},\"datePublished\":\"2025-09-22T12:25:54+05:30\",\"dateModified\":\"2026-09-01T15:51:52+05:30\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#webpage\"},\"articleSection\":\"Adobe, AdobeExperienceManager, AdobeGraniteSAML, AEM, AEMSAMLAuthenticationusingMicrosoftAzureAD, AEMSAMLSSO, AEMSSO, AzureActiveDirectory, AzureADSSO, IntegrateSAMLwithSSO, MicrosoftAzureAD, MicrosoftEntraID, SAML, SAMLAuthentication, SAMLIntegration, SAMLSSO, SingleSignOn\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/adobe\\\/#listItem\",\"name\":\"Adobe\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/adobe\\\/#listItem\",\"position\":2,\"name\":\"Adobe\",\"item\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/adobe\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#listItem\",\"name\":\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\\\/AMS platform.\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#listItem\",\"position\":3,\"name\":\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\\\/AMS platform.\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/category\\\/adobe\\\/#listItem\",\"name\":\"Adobe\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\",\"name\":\"TO THE NEW Blog\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/raja-karuppusamy\\\/#author\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/raja-karuppusamy\\\/\",\"name\":\"Raja Karuppusamy\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#authorImage\",\"url\":\"https:\\\/\\\/newersworld-sf-static.tothenew.net\\\/prod\\\/profilePicFolder\\\/2fe8a584-e4a5-4bf1-9993-c8fc4f58d975_4087-Raja-Karuppusamy-PROFILEPICTURE.jpeg\",\"width\":96,\"height\":96,\"caption\":\"Raja Karuppusamy\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#webpage\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/\",\"name\":\"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\\\/AMS platform. | TO THE NEW Blog\",\"description\":\"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\\\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/raja-karuppusamy\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/author\\\/raja-karuppusamy\\\/#author\"},\"datePublished\":\"2025-09-22T12:25:54+05:30\",\"dateModified\":\"2026-09-01T15:51:52+05:30\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/\",\"name\":\"TO THE NEW Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.tothenew.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog","description":"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol","canonical_url":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#article","name":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog","headline":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform.","author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/raja-karuppusamy\/#author"},"publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.tothenew.com\/blog\/wp-ttn-blog\/uploads\/2025\/08\/1.1.png","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#articleImage"},"datePublished":"2025-09-22T12:25:54+05:30","dateModified":"2026-09-01T15:51:52+05:30","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#webpage"},"isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#webpage"},"articleSection":"Adobe, AdobeExperienceManager, AdobeGraniteSAML, AEM, AEMSAMLAuthenticationusingMicrosoftAzureAD, AEMSAMLSSO, AEMSSO, AzureActiveDirectory, AzureADSSO, IntegrateSAMLwithSSO, MicrosoftAzureAD, MicrosoftEntraID, SAML, SAMLAuthentication, SAMLIntegration, SAMLSSO, SingleSignOn"},{"@type":"BreadcrumbList","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.tothenew.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/adobe\/#listItem","name":"Adobe"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/adobe\/#listItem","position":2,"name":"Adobe","item":"https:\/\/www.tothenew.com\/blog\/category\/adobe\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#listItem","name":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform."},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#listItem","position":3,"name":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform.","previousItem":{"@type":"ListItem","@id":"https:\/\/www.tothenew.com\/blog\/category\/adobe\/#listItem","name":"Adobe"}}]},{"@type":"Organization","@id":"https:\/\/www.tothenew.com\/blog\/#organization","name":"TO THE NEW Blog","url":"https:\/\/www.tothenew.com\/blog\/"},{"@type":"Person","@id":"https:\/\/www.tothenew.com\/blog\/author\/raja-karuppusamy\/#author","url":"https:\/\/www.tothenew.com\/blog\/author\/raja-karuppusamy\/","name":"Raja Karuppusamy","image":{"@type":"ImageObject","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#authorImage","url":"https:\/\/newersworld-sf-static.tothenew.net\/prod\/profilePicFolder\/2fe8a584-e4a5-4bf1-9993-c8fc4f58d975_4087-Raja-Karuppusamy-PROFILEPICTURE.jpeg","width":96,"height":96,"caption":"Raja Karuppusamy"}},{"@type":"WebPage","@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#webpage","url":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/","name":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog","description":"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.tothenew.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/#breadcrumblist"},"author":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/raja-karuppusamy\/#author"},"creator":{"@id":"https:\/\/www.tothenew.com\/blog\/author\/raja-karuppusamy\/#author"},"datePublished":"2025-09-22T12:25:54+05:30","dateModified":"2026-09-01T15:51:52+05:30"},{"@type":"WebSite","@id":"https:\/\/www.tothenew.com\/blog\/#website","url":"https:\/\/www.tothenew.com\/blog\/","name":"TO THE NEW Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.tothenew.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"TO THE NEW BLOG","og:type":"blog","og:title":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog","og:description":"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol","og:url":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/","og:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","og:image:secure_url":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png","twitter:card":"summary","twitter:site":"@tothenew","twitter:title":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform. | TO THE NEW Blog","twitter:description":"1. Introduction The article will explain how to configure Single Sign On (SSO) on an AEM Author\/Publisher instance using Microsoft Azure AD. SAML is a widely adopted, industry-standard protocol for enterprise SSO. SSO allows users to log in once and gain access to multiple systems. SAML (Security Assertion Markup Language) acts as an industry-standard protocol","twitter:image":"https:\/\/www.tothenew.com\/blog\/wp-content\/themes\/ttn\/images\/social-logo.png"},"aioseo_meta_data":{"post_id":"68055","title":null,"description":null,"keywords":[],"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":[],"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"limit_modified_date":false,"created":"2025-08-29 11:31:21","updated":"2026-09-01 10:21:54","focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.tothenew.com\/blog\/category\/adobe\/\" title=\"Adobe\">Adobe<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tStep-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform.\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.tothenew.com\/blog"},{"label":"Adobe","link":"https:\/\/www.tothenew.com\/blog\/category\/adobe\/"},{"label":"Step-by-Step Guide to Configure AEM SAML Authentication using Microsoft Azure AD in On-Prem\/AMS platform.","link":"https:\/\/www.tothenew.com\/blog\/step-by-step-guide-to-configure-aem-saml-authentication-using-microsoft-azure-ad\/"}],"_links":{"self":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/68055","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/users\/1545"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/comments?post=68055"}],"version-history":[{"count":23,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/68055\/revisions"}],"predecessor-version":[{"id":81999,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/68055\/revisions\/81999"}],"wp:attachment":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/media?parent=68055"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/categories?post=68055"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/tags?post=68055"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}