|   |  Add Azure AD SSO server / Edit Azure AD SSO server | 
| Add or update Azure AD SSO servers. | 
| Sample Configuration | |
|---|---|
| Parameter | Mandatory | Default | Description | 
|---|---|---|---|
| ServerName | Yes |   Name of the server. ServerName confines to: 
  | |
| ApplicationID | Yes |   Application (client) ID. Copy it from Azure portal > App registrations. ApplicationID confines to: 
  | |
| TenantID | Yes |   Directory (tenant) ID associated with an organizational directory. Copy it from Azure portal > App registrations. TenantID confines to: 
  | |
| ClientSecret | Yes |   The password used by the firewall to authenticate its SSO server connection with the Azure application. Copy it from Azure portal > App registrations > Certificates & secrets. ClientSecret confines to: 
  | |
| RedirectURI | Yes |   FQDN or IP address of the firewall. RedirectURI confines to: 
  | |
| DisplayName | Yes |   Enter "upn". The firewall uses the UserPrincipalName (UPN) to create the user's display name locally. DisplayName confines to: 
  | |
| EmailAddress | Yes |   Enter "email". EmailAddress confines to: 
  | |
| UserType | Yes |   Type of user. UserType confines to: 
  | |
| identifiertype | Yes |   For administrators, enter "roles" or "groups". identifiertype confines to: 
  | |
| identifiervalue | Yes |   Role configured in the Azure portal under App roles. identifiervalue confines to: 
  | |
| profileidentifier | Yes |   Administrator profile for the matching role or group. profileidentifier confines to: 
  | |
| FallbackUserGroup | Yes |   User group to assign if the firewall doesn't find a matching user group locally. FallbackUserGroup confines to: 
  | 
| Operation | Status | Message | 
|---|---|---|
| Add Azure AD SSO server | 200 | |
| Add Azure AD SSO server | 500 | |
| Add Azure AD SSO server | 502 | |
| Add Azure AD SSO server | 503 | |
| Edit Azure AD SSO server | 200 | |
| Edit Azure AD SSO server | 500 | |
| Edit Azure AD SSO server | 502 | |
| Edit Azure AD SSO server | 503 |