Configure SAML Single Sign-On (SSO) with Brevo

clickable_banner-pricing_9_en-us.png

✅ Plan availability
SAML SSO is included in the Enterprise plan and available as an add-on on the Professional plan ($324/month).

SAML Single Sign-On (SSO) adds an extra layer of security to your Brevo account. Users are authenticated by a trusted third-party identity provider (IDP) and can access Brevo with a secure token, without entering a separate password.

About SAML Single Sign-On (SSO) in Brevo

The following frequently asked questions explain how SAML SSO works, which providers are supported, and the different setup options available.

Which identity providers does Brevo support?

Brevo supports the following identity providers for SAML Single Sign-On (SSO) and provides dedicated setup documentation for each:

What SAML method does Brevo use to interact with identity providers?

When a user logs in with SAML SSO, Brevo sends an authentication request to the IDP using HTTP-Redirect Binding, redirecting the user to the IDP login page. 

After successful authentication, the IDP returns a secure token to Brevo via HTTP-POST Binding, which Brevo verifies to grant access without a separate password.

Who can access Brevo via SAML SSO?

We offer different setup options depending on who should access Brevo via SAML SSO:

Admin account only (Enterprise plan)

Only the admin user can log in via SAML SSO. Sub-organization users continue using their passwords.

This setup is done from the Admin account. Follow the setup procedure for your identity provider and do not select the option Force sub-organization users to log in with master IDP at the end of the process.

Admin account and all sub-organizations (Enterprise plan) 

Both the admin user and sub-organization users can log in via SAML SSO.

This setup is done from the Admin account. Follow the setup procedure for your identity provider and select the option Force sub-organization users to log in with master IDP at the end of the process.

Specific sub-organization (Enterprise plan) 

SAML SSO is activated for a specific sub-organization, while the admin and other sub-organizations continue using passwords.

This setup is done directly from the sub-organization. Follow the setup procedure for your identity provider.

❗️ Important

Enabling SSO for multiple specific sub-organizations requires repeating the setup and creating a separate application for each sub-organization in your IDP. Note that not all identity providers may support this setup.

Standard Brevo account (Professional and Enterprise plans) 

SAML SSO is activated for a standard Brevo account, allowing all users of that account to log in via SAML SSO.

This setup is done directly from the Brevo account. Follow the setup procedure for your identity provider.

Good to know

  • We recommend asking an IT administrator familiar with your identity provider to handle the SAML SSO configuration.
  • Setting up SAML SSO requires some back-and-forth between Brevo and your identity provider. Keep both platforms open in separate tabs, as you will need to copy and paste values between them during the process.
  • The screenshots in this article show the New Admin account interface. If you are using a Classic Admin account, a sub-organization, or a standard Brevo account, the interface may look slightly different, but the process stays the same.

Configure SAML Single Sign-On (SSO) with Brevo

The configuration for SAML SSO varies depending on your identity provider. Use the following tabs to view instructions for Microsoft Entra ID, Okta, or Auth0.

Microsoft Entra ID OktaAuth0

Step 1: Activate SAML SSO in Brevo

First, activate SAML SSO in Brevo:

  1. In Brevo, access the SAML SSO page. The path URL differs depending on whether you are accessing it from an Admin account or from a sub-organization or standard Brevo account.
    • From an Admin account, go to Security > SAML.
    • From a sub-organization or standard Brevo account, click the account dropdown and select Security > SAML
  2. Activate the Allow SAML Authentication option.
    new_SAML_enable-SAML_en-us.png

Step 2: (Optional) Download Brevo's certification for stronger encryption

✅ Plan availability
The option to generate and download Brevo's certification for stronger encryption is available on demand for Enterprise plans only. Contact your dedicated Customer Success Manager to request activation.

By default, Brevo’s basic SAML SSO configuration supports one-way encryption. You can download Brevo’s certificates to configure two-way encryption and improve security:

  1. In Brevo, select the Generate and download Brevo's certification for stronger encryption option.
  2. Click Download Brevo's certification. A file named "public.cer" is downloaded on your computer.
    new_SAML_generate-certificate_en-us.png

You will upload this file into Microsoft Entra ID during step 6.

Step 3: Create the Brevo application in Microsoft Entra ID

Start by creating a new application for Brevo in your Microsoft Entra admin center:

  1. Open a new tab in your browser and log in to your Microsoft Entra admin center.
  2. In the navigation menu, go to Identity > Applications > Enterprise applications.

  3. Click + New application.
    SAML_create-application_en-us.jpeg

  4. Click + Create your own application.
    SAML_create-own-application_en-us.jpeg

  5. Name the application (e.g., "Brevo").
  6. Select Integrate any other application you don't find in the gallery (Non-gallery).
  7. Click Create.
    SAML_create-brevo-application_en-us.jpeg

Step 4: Assign users to the Brevo application in Microsoft Entra ID

Allow users to sign in to Brevo using SAML SSO by assigning them to the Brevo application in Microsoft Entra ID:

  1. If you haven't done so already, create the users who will log into Brevo using SAML SSO in Microsoft Entra ID. To learn more, check Microsoft Entra's dedicated documentation.
  2. In the navigation menu, go to Identity > Applications > Enterprise applications.
  3. Select the Brevo application.
    SAML_brevo-application_en-us.jpeg
  4. Go to Users and groups.
  5. Select Add user/group.
    SAML_add-user-group_en-us.jpeg
  6. Under Users and groups, click None Selected.
  7. Select the users that you want to assign to the Brevo application and click Select.
  8. Under Select a role, click None Selected.
  9. Select the role that you want to assign to the users and click Select.
  10. Click Assign to assign the users to the Brevo application.
❗️ Important
To access your Brevo account via SAML SSO, ensure that the user's email address is both added to Brevo and configured in Microsoft Entra.

Step 5: Configure SAML SSO in Microsoft Entra ID

Now, activate and configure SAML SSO in Microsoft Entra ID:

  1. Go to Single sign-on.
  2. Select SAML as the single sign-on method.
    SAML_select-SAML_en-us.jpeg
  3. In the 1. Basic SAML Configuration section, click Edit.
    SAML_edit-basic-configuration_en-us.jpeg

  4. In the Identifier (Entity ID) field in Microsoft Entra ID, click Add identifier and enter:
    https://account-app.brevo.com/account/
    saml_microsoft-entra_entity-id_en-us.jpeg
  5. In the Reply URL (Assertion Consumer Service URL) field in Microsoft Entra ID, click Add reply URL.
  6. Copy the value from the Callback URL field in Brevo and paste it into the Reply URL (Assertion Consumer Service URL) field in Microsoft Entra ID.
    new_saml_microsoft-entra_callback-url_en-us.png
  7. Copy the value from the Login URL field in Brevo and paste it into the Sign on URL field in Microsoft Entra ID.
    new_saml_microsoft-entra_login-url_en-us (1).png
  8. Click Save.
  9. Close the side panel.

Step 6. (Optional) Upload Brevo's certification into Microsoft Entra ID

If you have previously downloaded Brevo's certification, upload it to Microsoft Entra ID:

  1. In the 3. SAML Certificates section, click Edit next to Verification certificates.
    SAML_edit-certificate_en-us.jpeg
  2. Select the Require verification certificates option.
  3. Click Upload certificate
    SAML_upload-certificate_en-us.jpeg
  4. From your computer, select Brevo's certification named "public.cer" and click OK.
  5. Click Save.

Step 7: Configure SAML SSO in Brevo

Now, configure SAML SSO in Brevo:

  1. In the 3. SAML Certificates section in Microsoft Entra ID, copy the value from the App Federation Metadata Url field and paste it into the Metadata address field in Brevo.
    new_SAML_copy-metadata_en-us.png
  2. In the 4. Set up [Application Name] section in Microsoft Entra ID, copy the value from the Login URL field and paste it into the Sign-on URL field in Brevo.
    new_SAML_copy-login-url_en-us.png
  3. In the Entity ID field in Brevo, enter:
    https://account-app.brevo.com/account/
  4. In the Email fieldname field in Brevo, enter:
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
  5. In the User ID field in Brevo, enter:
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    new_SAML_enter-values_en-us.png

Step 8: (Optional) Activate SAML SSO for sub-organization users in Brevo

💡 Good to know
The option to activate SAML SSO for sub-organization users is available only from an Admin account.

By default, SAML SSO is activated only for Admin users while sub-organization users need to log in to Brevo via the standard Brevo login page using their regular credentials.

To activate SAML SSO for sub-organization users as well, select the Force sub-organization users to login with master IDP option.

new_SAML_disable-sub-organizations_en-us.png

Step 9: Verify your SAML configuration

After configuring SAML SSO, click Verify to check your configuration:

  • ✅ If your SAML configuration works, click Save the settings.
  • ❌ If your SAML configuration doesn't work, review each step of the configuration and re-verify.

You've activated SAML SSO authentication on your Brevo account. Now, users can log in from the SSO login page.

⏭️ What's next?

🤔 Vous avez des questions ?

Pour toute question, n’hésitez pas à contacter notre service client en créant un ticket à partir de votre compte. Si vous n’avez pas encore de compte, vous pouvez nous contacter ici.

Si vous avez besoin d'aide pour un projet impliquant Brevo, nous pouvons vous mettre en relation avec une agence partenaire Brevo.

💬 Cet article vous a-t-il été utile ?

Utilisateurs qui ont trouvé cela utile : 1 sur 2